active directory group attestation

And who should be responsible for it?

How is your Active Directory (AD) being managed? Do you have any orphaned groups (groups without owners)? Are there groups that have outlived their purpose? Do you have users that are members of groups and they no longer need to be part of these groups? An ongoing attestation of groups is key to answering these questions.   Group objects in your directories tend to…

Expired Groups

The End of Groups: The Case for Group Expiration

Many directories contain groups so old that even you don’t know why they exist, who uses them, and what they provide access to. It’s a more common problem than you’d think.  “We should be deleting groups then, right?” might be your initial response.  And while the answer is “yes” in the short run, the reality is…

Employee System of Record

Your Directory Needs an Employee System of Record (ESR)

The advent of cloud-based applications syncing their directories with source directories like Active Directory has forced organizations to think about the validity of the directory data. Some organizations look to users to self-service their account details (with no real incentive to do so, though), while others look to IT to keep the directory current (more…

Managing

Managing LDAP groups in the Enterprise

Managing LDAP groups in the Enterprise Today’s enterprise-sized businesses have moved beyond the single on-premises directory. The need to leverage platforms and applications that reside outside the four proverbal walls of the organization have resulted in an uptick in the use of 3rd party LDAP directories within these environment, whether hosted on-prem, in a corporate…

office 365

Managing Microsoft 365 (and Office 365) Groups in the Enterprise

The shift to the cloud has many organizations focused on the productivity features available in a given cloud suite. And M365 is no exception. There’s a long list of applications in M365 – a list that’s continually growing. But, Using M365 isn’t just about productivity; it’s also about security and control for IT.  And, like…

Google Workspace management

Managing Google Workspace Groups in the Enterprise

At the core of every environment that is designed to make people productive is the need “under the hood” to be able to establish what users of that environment can do, what they can access, and – in many cases, how they can easily communicate with other users. The long-standing methodology (with a few exceptions…

Microsoft azure

Directories, How Many Are You Really Managing?

Directories, How Many Are You Really Managing? Directories came from a simpler time – one where a single, on-premise directory was enough. But recent shifts in how businesses leverage technology – such as the digital transformation, and the move to cloud-based applications and infrastructure –  have given way to use of SSO (link), concepts like…

webSSO

The Productivity Gap in Single Sign-On – Accuracy In Directory is Key

In my last article, I introduced the merits of using Single Sign-On within your organization. In it, I discussed the possible security gaps that can multiply as you, in essence, extend your on-prem directory service to include multiple directories. And, while there are security benefits for using SSO – centralized policies and administrative work (which…

Active Directory

2018: Changing the “Directory” Definition

Here at Imanami, we’ve spent the last number of years talking about the need to keep Active Directory secure. While still a valid and pertinent message today, a lot of changes in the industry give us pause to consider Active Directory’s role in the larger picture, and to reflect on how the very same group…

Group Lifecycle Management

AD Group Lifecycle Management – Group Attestation

Because of the lack of attention groups get throughout their lifetime, one of the greatest security risks an organization faces is when a group lives too long. Think about it – you have groups that exist today that, despite having a clear understanding of the logic behind its membership, you have zero idea why it’s…