GroupID 11 Sneak Peek

Did you miss the session? No worries. Here is recording of some of the awesome features that will be featured in Version 11.

GroupID 11 Sneak Peek

Did you miss the session? No worries. Here is recording of some of the awesome features that will be featured in Version 11.

GroupID 11 Sneak Peek Q&A

For those who witnessed Imanami’s GroupID 11 Sneak Peek, below are the
questions that participants asked along with detailed answers.

Did not know you guys had a mobile app, does it support both Android and iOS?

Yes, both an Android and iOS mobile app are available for download. The mobile application, first released for use with GroupID v9 continues to be improved. The same app is also available in the Windows Store.

Can we have Multiple SQL servers in cluster? Meaning Master and the Slaves all have their own SQL

GroupID is abstracted from the SQL deployment choices in infrastructure.

Can GroupID manage groups in Azure AD or Gmail via native connectors?

GroupID already support native Azure AD directories via native identity store providers. This feature was added in a previous release although many customers still leverage a local on-prem Active Directory to connect to and synchronize from. This is not a requirement but is a deployment choice. It is possible to connect to an on-prem AD and Azure AD at the same time or have one directory slaved to the other using Azure AD Connect. This release of GroupID adds additional functionality in the native connections to Azure AD centered around the use of groups in Azure AD. The abstraction for identity stores allows GroupID to address additional identity stores independent of the business logic that makes GroupID awesome such as dynamic membership, attestation, life cycle, temporary membership, user life cycle, and more. At this time, Google Workspace is only supported using directory synch, but our identity store abstraction will allow for the creation of a direct integration without the need of an Active Directory. This feature is not yet available but is planned under the enhanced capabilities of GroupID 11.

Is there a seamless upgrade path from GroupID 10 to 11 without having to rebuild/redo configurations In Automate and Self service?

Portal configurations made in GroupID 10 can be migrated to GroupID 11. Custom configurations however (changes made to markup or script, etc) are outside the scope of the upgrade process. We encourage our customers to discuss an upgrade plan for GroupID 11 so that we can help you ensure a smooth upgrade that realizes all of the unique configurations you have implemented.

Will we be able to update Cloud/Azure/Exchange Online groups via on-prem SQL database sources?

Yes, one of the great benefits of GroupID has been the ability to use database queries to establish membership in groups within your on-premise Active Directory. GroupID 11 allows you to do effect the same in your cloud directory as well.

Could you explain a bit in detail how the private cloud hosting feature would look like?

With the ability to “deploy” critical components of GroupID such as the central data service, web portal, etc to either an IIS instance or a Docker container, a complete scalable solution independent of Windows servers is possible. The choice of hosting platform is really for you. We are working on documentation at the time of this presentation and will include some documented examples of best practices in deployment. Of course, our support team will also be available when you are ready to help guide you in a chose deployment scenario.

Will end users be able to generate these new report options for groups?

Yes, if so delegated by role, end users can create, and view reports!

Will the Auto DLs schedule report be available on web rather then being send in the email?

GroupID reports can be generated and viewed on the web but can also be configured to be delivered in email. From the web, you can delegate visibility to users by role so that the right audience gets access to important data from the reports.

Does the web portal still run on IIS? Can we still customize the portals based upon security role?

Yes, IIS can still be a host for GroupID and like with the Self Service portal in the past, you can configure access to features and UI based on roles. In addition, this applies across the board including to the admin web based console.

What type of applications are supported with your single sign on?

GroupID supports SSO (single sign on) Authentication internally to all GroupID web based portals. The authentication capability also allows for consumption of external SSO providers that support standard SAML 2.0 tokens. Both IdP and SP initiated flows are possible. With release 11, GroupID adds the ability to support authentication services to other external applications that use SAML 2.0 in both IdP and SP flows. GroupID allows for the mapping of attributes to be exposed for claims to match the specific needs of each external application.

Is this version faster than what we have now?

Yes. In every facet of use, our team has worked tirelessly to increase speed/performance of all operations. Areas of focus specifically are in dynamic changes and user web experiences. In fact, a concerted effort has been made in the area of usability to reduce the number of clicks in typical operations. We also unified the web application experience to further reduce the workflow that is typically experienced when moving between multiple GroupID operational processes.

Request Inbox performance?

The request inbox reflects workflows targeted to the user. As with other areas of the product, speed improvements have been realized here with paginating of large data and controlling the filtering mechanisms for both your requests and those indirectly targeting you (additional ownership).

Is the Group ID 11 compatible with .net 3.8?

GroupID 11 is based on .net core abstracting dependencies on version specific .net versions. From the initial web console install, you will be able to deploy services to one of several platforms including Linux hosted Docker containers!

Can this still be an on-prem app?

Yes, GroupID can be deployed on-prem to internally hosted IIS server as well as internally hosted Docker container.

How group id will integrate with MS teams?

GroupID already supports Microsoft Teams by virtue of its ability to natively support Microsoft 365 Office groups. In addition, by deploying our Teams client in your Teams environment will give you the added benefit of performing GroupID related capabilities directly within Teams. This includes applying business logic such as temporary membership and ongoing attestation.

Is the API available for use now in version 10 ?

GroupID only includes PowerShell for orchestration. In version 11 the appropriate license will get you access to our RESTful API and Power Automate endpoints.

Are there any specific enhancements to Automate.

Yes, there are many, but my personal favorite is the management completely from a remote web browser. All of the power of Automate as you know it today with increased independence of hosting architecture plus abstraction from the identity store allows you to get the best in possible automated membership. Plus, role based access allows an admin to delegate portions of Automate style functionality to other users to get done what their role needs without giving access to everything.

Can you tell us more about the REST API capabilities?

A fully features RESTful API is available in GroupID 11 with the ability to implement a full client to GroupID 11. Any feature possible in the portal to create, update, renew, delete, etc is possible from the API. If you wanted to rewrite your own mobile app or your own portal, it is possible!

Thank you. This is a great selling point. You described our exact scenario.(Ryan (Unverified) asked "Will we be able to update Cloud/Azure/Exchange Online groups via on-prem SQL database sources?")

YES! We are excited to see the hundreds of ways our customers do this today with their on-prem directories doing so with their cloud based identity stores.

When can we see the system requirements so we can get hardware ordered? Since now a web app, can it be used behind a load balancer if we have mutliple servers over multiple datacenters?

We are working on releasing a full minimal system requirement document right now and expect to publish it soon so that our clients can prepare. The footprint will not be larger than what is necessary to deploy GroupID 10 right now in the same manner. Additional deployment scenarios however (for example using Docker) will require some software configuration not presently needed for GroupID 10.

We have a hybrid environment. Looks like we can now support our MS365 environments?

This release includes many improvements for your hybrid environment but is not the first GroupID release to support MS365. Some of the most notable improvements for the administrator is a singular portal for simultaneous administration of objects in multiple identity stores. In addition, services enabled through MS365 such as Office groups that exist only in the cloud are able to take advantage of the same business processes and policies such as membership life cycle in the same manner that these have been applied to your on-prem directory in the past.

When can I get it? and follow up: Can we test it in our lab before it ships?

The official date of release of GroupID 11 has not been finalized but we are currently targeting a Q3 2021 release with customer access to builds in the Q2 of this year. As with all releases, those with active entitlements to upgrades will be able to get license keys to this product when released and be able to put into their lab. For those parties interested in our early adopter program, we are accepting inquires from interested parties. Please contact our support department or your account representative. The early adopter program includes some minimal baseline expectations for participation. Details and applications will be made available soon. Participation in this program is highly encouraged and is the best way to provide feedback ahead of product releases.

We use Teams in our environment, what are some of the ways GroupID is better for us?

Microsoft Teams has become Microsoft’s fastest growing business application in their history. This was the case even before the work from home explosion in the wake of the worldwide pandemic. Like many of our customers, Imanami is also a user of Microsoft Teams and has become dependent on these tools to ensure ongoing communication in our organization. Microsoft Teams leverages an Office Group to facilitate management of Team membership. With GroupID’s native support for the Azure Active Directory identity store, we also include management of groups that manage teams. We recognize however, while that is awesome, our customers expect a unified experience. Workers are now living their professional lives through collaboration. GroupID has been enhanced such that you are able to perform all of the best practices when it comes to automated and delegated group/list management and do so natively from within Teams with an application that plugs directly into your Teams experience.

Though the dashboard, can we make connection to SQL DB's to populate membership?

Yes, GroupID 11 as with previous versions, supports integration to SQL databases to determine membership in groups. With this version, this configuration occurs in the web admin portal. In addition, it will be possible as an admin to configure the connections and delegate sub-configurations to helpdesk workers to leverage for criteria building.

We have seen issues with browser compatibility, will 11 support a wider range of browsers?

GroupID 11 is tested with all of the latest browsers including but not limited to Edge (Chromium), Chrome, Firefox, Opera, and Safari.

Is it possible to be able update O365 group membership based on a membership of On-Prem Active Directory membership?

Yes! This is a great new features we have introduced in this release where you can synchronize membership of a group from one identity store to a group in another. This synchronization can happen in either direction.

I've had a user ask me, similar to managing the group he ownes, in the future could he manage shared mailbox permissions?

GroupID currently does not have the ability to delegate the ownership of a shared mailbox, but I have just added that to our feature request queue. Thank you, our customer feedback will always make our product better for everyone.

I love the PowerAutomate integration. Can you give an example of what we might use this for pertaining to smartgroups?

We have so many ideas and cannot wait for the ideas our customers come up with. Some examples of things you can do are from a triggered workflow in GroupID, branch out into a Power Automate flow and seek serial or parallel approvals. Or, from one of these flows, trigger additional orchestration against other products such as create a file, or mark off something in a SharePoint list or To Do list! The options are literally limited only by our imagination!

If I'm currently on v10, what is the path to upgrade to v11? Is it simply opening a case with Imanami tech support?

Exactly! Our world class support will be able to schedule time with you to discuss the best steps to take for your individual environment. We know that every one of our clients has unique situations that should be considered.

O365 dynamic membership update is great, but it is missing a lot of attributes that AD has

Correct, in addition to requiring a premium subscription, native dynamic groups in MS365 are limited to a small subset of attributes. With GroupID, you can leverage extended set of attributes and combine with external sources along with the hundreds of other advanced features to realize all best practices to automating and delegating changes made to membership in groups.

Can we still use our own single sign on?

Yes. The choice to use GroupID as the authoritative source for all of your web applications is possible, or you can use an external provider. The choice is yours.

Who can see the reports if they are on the web?

GroupID’s portal experience is governed by roles as configured by an administrator. Through these definable roles, you can delegate both the creation and view of reports to any user based on those roles. A common use case is where a custom report is needed on an ongoing basis by a department head. This department head may need to take corrective action based on the results of the report. The administrator would assign the report to the user or the role the user is included in. The user (department head) gains access to this report with he rights delegated (read only, regenerate, update, etc) and takes action based on the output accordingly. Reports are an integral part of the GroupID user experience empowering your organization with important visibility.

Any improvement in workflow approvals?

Yes, we are happy to that workflow has been improved in many ways. In the last release, we introduced the concept of workflow acceleration to ensure that no flow would go unanswered by implementing a policy whereby we allow the administrator to configure the promoting of a workflow that was left for a user to their respective manager. We received such positive feedback on that feature improvement but with requests to allow for more custom flow paths. To accomplish this level of customization, we are introducing the ability to trigger Power Automate flows from a workflow trigger. Within Power Automate, you can orchestrate additional steps including parallel and serial workflow processes. Integrate flows with other external business processes, leverage virtual agent bot mechanisms, and much more. We are excited to hear how our customers take advantage of this extensible workflow capability.

Multiple Master servers in the same cluster?

SQL clustering is typically implemented in active/passive configurations for high availability.

Allow users to leave a Private group?

The nature of a private group is one that is statically managed. To enable the option for users to leave a group but not allow them to join a group, it is a good use-case for semi-private group with separate join and leave workflow targeting and handling. This is especially true with the custom workflow capabilities now possible through Microsoft’s Power Automate.

What will the upgrade process look like when moving from 10 to 11?

As with all upgrades, moving from version 10 to 11 will be the easiest migration. The upgrade includes both in-place upgrade (most seamless) and migration capabilities. We understand that identity infrastructure can be complex so we encourage you to work with our support team on discussing any questions and plan appropriately for this version. With your active software upgrade plan as the primary element of our maintenance program, you are entitled to the upgrade license and support to help ensure a successful deployment. Additional deployment scenarios including remote container deployments actually makes this upgrade easier than any upgrade in the past.

Can it be put behind a load balancer?

Yes!

We use Self Service portal. Did I see that the admin is no longer MMC, it is on the web now too? If so, does that mean I can access from any machine?

Yes, GroupID continues to improve in many areas and one of the most important areas is in the area of administrative accessibility.

Does anyone expose the Self Service Password Portal externally without any security concerns? What safeguards should be put in place?

Many of our customers do expose GroupID, and specifically user management features such as password reset. There are some security concerns depending on your environment. As with other things, our support can discuss best practices to ensure a safe deployment. We believe in this case, being able to access password reset functionality from your browser and from our mobile app (extremely valuable) is key to delegating this capability and lightening the load off your helpdesk team.

We are currently running Version 9 on a server - what will be the upgrade path if we want to run it in an AWS container - Is there an easy way to backup the settings and move/upgrade it?

Upgrading from version 9 will be possible. For your scenario, you will deploy to the container first and then migrate your relevant data. Our support will help you in this process to ensure success!

Ask A Question
Type in additional questions you may have here.

If you want more information,
please contact us at: [email protected]