November 7, 2017 By Raghu Dev 3 min read

This is follow-up to a previous article about access management. Be sure to read that first installment for the full story.

When you have several heritage access management or access governance tools spread throughout the corporation, the view of an employee’s access is splintered. When security solutions are siloed, owners of applications and purveyors of shadow IT within the business unit often fend for themselves by creating spreadsheets, scripts and programs. They also worry about conforming to policies and maintaining compliance to pass internal and external audits.

To shine a light on this disjointed access data, employees, managers, security professionals, application owners and auditors need a single view of all accesses throughout the organization.

A Consolidated View of Actionable Access Data

When presented on a single pane of glass, this access data is powerful. It helps employees understand their privileges and enables them to track their own requests and approvals. It also helps managers and, in same cases, application owners control access and determine what level of access to grant employees.

With a consolidated view of access data, organizations can move from simply seeing data to acting on it. Actionable dashboards enable security teams to bring visibility to otherwise hidden data, which is the first step toward access management transformation.

For managers, application owners and employees alike, user experience can be a double-edged sword. Many employees cite lack of a single tool to view access data as a key pain point. The need to use several disparate access management tools is not conducive to productivity. Furthermore, a fatigued user experience can lead employees to adopt alternate access methods that may be insecure.

A Manager of Managers

To consolidate this disjointed access data into a single pane of glass, we created a manager of managers model. We integrated heritage access management tools via connectors and simple file transfer methods to our centralized access platform. The critical step here is to design a many-to-one data model.

We avoided boiling the ocean. Being surrounded by agile gurus and true practitioners, we used small, iterative steps to achieve our goal. We knew it would be hard to come up with a model that would never change, so we made sure our data model, while being well-managed and suited to fit most of the heritage tool’s requirements, remained flexible. Flexibility can be both a boon and curse, however, because with greater flexibility comes greater responsibility.

Transformation should not be merely a lift-shift process — it must improve upon the data quality and, especially, the process. To boost data quality, the security team should question entitlements, roles and groups, representing only the best and most useful. For example, the team can improve the process by reducing the number of steps required to request access. The final step is to introduce new functionalities, such as risk-based access controls.

Ensuring a Silent Access Management Transformation

To ensure a nondisruptive, or silent, transformation, the first step is to represent the access data from heritage tools in the centralized access platform. Then create a connector using the access management platform as a one-stop shop to view all accesses. Next, build two-way connectors to heritage access management tools. This enables the platform to process access requests and send the data back to the heritage tools.

Once users begin to use this platform for all their access-related needs, unplug applications from the heritage tools and move them to the new platform. This virtually seamless transition achieves our silent transformation goal.

Stay tuned for the third installment, in which we will discuss the next steps in your access management transformation, such as managing security’s impact on the business and introducing risk-based access controls into the environment.

More from Identity & Access

Taking the complexity out of identity solutions for hybrid environments

4 min read - For the past two decades, businesses have been making significant investments to consolidate their identity and access management (IAM) platforms and directories to manage user identities in one place. However, the hybrid nature of the cloud has led many to realize that this ultimate goal is a fantasy. Instead, businesses must learn how to consistently and effectively manage user identities across multiple IAM platforms and directories. As cloud migration and digital transformation accelerate at a dizzying pace, enterprises are left…

“Authorized” to break in: Adversaries use valid credentials to compromise cloud environments

4 min read - Overprivileged plaintext credentials left on display in 33% of X-Force adversary simulations Adversaries are constantly seeking to improve their productivity margins, but new data from IBM X-Force suggests they aren’t exclusively leaning on sophistication to do so. Simple yet reliable tactics that offer ease of use and often direct access to privileged environments are still heavily relied upon. Today X-Force released the 2023 Cloud Threat Landscape Report, detailing common trends and top threats observed against cloud environments over the past…

Artificial intelligence threats in identity management

4 min read - The 2023 Identity Security Threat Landscape Report from CyberArk identified some valuable insights. 2,300 security professionals surveyed responded with some sobering figures: 68% are concerned about insider threats from employee layoffs and churn 99% expect some type of identity compromise driven by financial cutbacks, geopolitical factors, cloud applications and hybrid work environments 74% are concerned about confidential data loss through employees, ex-employees and third-party vendors. Additionally, many feel digital identity proliferation is on the rise and the attack surface is…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today