pwshub.com

Exclusive: ConductorOne automates access controls for employees on the move

ConductorOne Inc., the developer of an identity governance platform, today announced access management capabilities to support joiners, movers and leavers, a human resources term for employee onboarding, internal transitions and offboarding.

The software enables businesses to onboard hundreds of users with a few clicks by using predefined profiles that specify the applications the user is allowed to access as well as privileges within those applications. Profiles typically map to jobs, roles or functions. The application also integrates with popular HR applications to detect employee departures or transitions to new jobs and adjust privileges accordingly.

Users are assigned membership in dynamic groups, which are automatically synchronized and kept up to date.

The company is addressing a common gap in enterprise security measures by automating the process of deleting user accounts and privileges. Its 2024 Identity Security Outlook Report found that 29% of businesses rely on manual processes to identify and deactivate orphaned accounts, while 6% don’t currently have a process.

Microsoft Corp.’s 2023 State of Cloud Permissions Risks Report said more than 60% of cloud identities are inactive and haven’t used any of their permissions granted in the last 90 days. These present a security risk because if credentials are compromised, an attacker can gain access to applications and data under an assumed account.

Hundreds of integrations

The four-year-old ConductorOne has built integrations with a large number of cloud and on-premises applications that comprise the most popular use cases, said co-founder and Chief Executive Alex Bovee.

“Although there are thousands and thousands of [software-as-a-service] apps, the reality is that probably 50 of them account for 90% of the usage and are the biggest pain points,” he said. “We have all the major SaaS and on-prem infrastructure systems covered, and most of those integrations support direct provisioning and de-provisioning.”

Direct provisioning grants specific access rights based on their role or responsibilities. For applications that don’t support that functionality, ConductorOne integrates with Slim, a framework that can be used to provision accounts.

Though many directory services support RBAC and automated provisioning, Bovee said, “they usually use Slim, and one of the limitations of that is that it tends to be group-based.” Group-based access can lead to granting more privileges than necessary because users often inherit all permissions assigned to the group, even if they don’t need them.

It also creates a security risk known as “privilege creep,” where users accumulate excessive access rights over time. All members of the group typically receive the same permissions, which doesn’t account for unique responsibilities within the same role.

Achieving fine-grained controls with group access requires defining controls at a granular level, Bovee said. For example, provisioning 100 Amazon Web Services Inc. cloud accounts, each with five roles, can require directory administrators to create 500 different groups.

“That’s ridiculous,” he said. “Administrators don’t want to configure all that stuff.  We cut out the middleman by saying we can do the direct provisioning. Tell us the access people need and we’ll take care of it for you.”

For de-provisioning, the software monitors the status of individual users in a companies HR system and can trigger workflows when people change jobs or leave the firm. It can also detect applications that haven’t been used for defined periods of time and trigger alert for access to be removed, thereby saving on software license costs.

Source: siliconangle.com

Related stories
1 month ago - This week brought yet another big shakeup at OpenAI, as Chief Technology Officer Mira Murati and others quit. But CEO Sam Altman seems to be cementing his control. And Chief Financial Officer Sarah Friar said in a memo that OpenAI’s...
1 month ago - Intel CEO Pat Gelsinger and key executives are expected to present a plan later this month to the company’s board of directors to slice off unnecessary businesses and revamp capital spending, according to a source familiar with the...
1 month ago - A top 10 Chinese fund manager has asked senior executives to return pay received over the past five years that exceeds a new cap, to tally with a government initiative promoting economic equality, said two people with direct knowledge of...
1 month ago - Samsung Electronics, the world's top maker of smartphones, TVs and memory chips, is cutting up to 30% of its overseas staff at some divisions, three sources with direct knowledge of the matter told Reuters. South Korea-based Samsung has...
1 month ago - Cloud cost optimization service provider Vantage today is adding support for Microsoft Corp.’s GitHub software version control and collaboration platform to its growing list of native integrations with cloud platforms and applications....
Other stories
49 minutes ago - There's nothing wrong with Devon Energy, but if you are looking for reliable high-yield dividend stocks you'll prefer these two alternatives.
49 minutes ago - Nvidia (NASDAQ: NVDA) has established itself as a successful investment over time, climbing more than 2,700% over the past five years. And momentum...
49 minutes ago - Now's a good time to warm up to these stocks that have recently received cold shoulders from investors.
50 minutes ago - The Invesco Solar ETF (TAN) is down 28% since the start of 2024 amid a difficult year for solar. Investors are worried about the election and interest rates.
50 minutes ago - (Reuters) -Deckers Outdoor shares jumped about 11% on Friday after the shoemaker raised its annual sales forecast betting on strong demand for its shoes and boots during the crucial holiday season. Trendy and innovative brands such as...