Dont Count Out Active Directory For Cloudy Future

  /     /     /  
Publicated : 22/11/2024   Category : security


Dont Count Out Active Directory For Cloudy Future


AD isnt going anywhere anytime soon



Because Active Directory (AD) was first developed in an era before SaaS services, some security proponents might make the case that
it hasnt adapted well enough and doesnt have the architectural flexibility to future-proof itself
within the increasingly cloud- and mobile-centric enterprise.
However, plenty of others out there will tell you not to count out AD yet. Not only is Microsoft gaining ground at honing ADs cloud capabilities through Windows Azure Active Directory and further refinements of Active Directory Federation Services (ADFS), but AD also is so completely ingrained within the fiber of just about every big enterprise out there that its not going anywhere anytime soon.
It will be a while before the dust settles around these [cloud identity providers], and in the near term its hard to see any one particular play winning, says Scott Crawford, analyst for Enterprise Management Associates. But you simply cant count out the value of Active Directory and of extending that from the enterprise to third-party services because it is so well-established.
[What IAM gaffes are you making? See
7 Costly IAM Mistakes
.]
Active Directory is a good platform for the cloud, says Phil Lieberman, founder of privileged identity management firm Lieberman Software.
AD can be used in so many ways. Microsoft is already using it for hundreds of millions of users as the basis for all of its cloud-based services, so scalability isnt an issue, Lieberman says. Its just a place to store stuff about identities and information about what they can do. Out of the box it ties all of the Microsoft stuff together, but there was never a restriction that said you couldnt use it for something else.
For example, you can change the schema and you can plug in another authenticator, he says.
It just uses Kerberos, but if you want to use something else or federate with something else, you can absolutely do that, Lieberman says.
With respect to federation, Jackson Shaw, senior director of identity management for Quest Software, a Dell company, says that too many cloud IAM providers with a clear agenda have overblown ADFS pain points to make it a bit of a four-letter word. But he believes that theres another four-letter word that IT buyers should use against these vendors: free.
One of the basic problems with ADFS that is overblown is just the fact that a customer will see that it needs to use some sort of a certificate or PKI and will immediately go deer in the headlights, he says. But the fact of the matter is any product that uses federation requires a certificate.
So even though the free product will cost money, the truth is that deployment headaches wont go away altogether. Shaw suggests customers use this fact to their advantage, even if they dont choose to use ADFS.
Free doesnt necessarily mean free, but it can also be used by customers as a bargaining chip when theyre buying software, he says. A customer whos smart about things and is educated a little bit can have that discussion -- can save themselves some money even when they know that they dont want ADFS or cant use it.
However, organizations should give the technology a chance, Shaw says. Though ADFS did face its share of early-generation roughness, Microsoft has been working the kinks out.
Microsoft gets things right after the third or fourth try. Theyve got the staying power to have that runway to perfect things before they take off, he says. I think you can see that with some of the work theyve done around integrating an on-premise directory with Office 365, theyre starting to sharpen their pencil.
Besides, Lieberman says, it would be somewhat disingenuous to say slow uptake of ADFS is failing on behalf of Microsofts part. He believes the question shouldnt be so much about why ADFS has not had tremendous uptake in the years it has been out, but instead why federation itself hasnt taken root in the enterprise.
Federation is rare in the enterprise today, he says. ADFS is an enabler for federation. Of course, its like a gym membership. You can buy it, but it doesnt mean youre going to go there.
In the end, the toughest nuts to crack around IAM deployments in the cloud, around single sign-on, and around federation really have nothing to do with AD or any individual technology. It all boils down to the underlying business processes these technologies are meant to facilitate.
Deployment to integrate identity management with these services is more than just connecting the dots through federation, Crawford says. Theres user management and provisioning, theres access management on the part of the target service, and then theres the granularity of access management.
But where things go wrong when putting all of these pieces together is that the IT departments dont understand the business processes theyll be built around to set up a successful deployment. And theres just no technology to solve that problem.
For a long time one of the biggest issues the systems integrators faced is that you have to understand how the organizations business process work to know what privileges would be correct, he says. A lot of times the customer didnt understand that themselves. So what started out as an identity management deployment often wound up being a business process management consulting engagement.
Have a comment on this story? Please click Add Your Comment below. If youd like to contact
Dark Readings
editors directly,
send us a message

Last News

▸ ArcSight prepares for future at user conference post HP acquisition. ◂
Discovered: 07/01/2025
Category: security

▸ Samsung Epic 4G: First To Use Media Hub ◂
Discovered: 07/01/2025
Category: security

▸ Many third-party software fails security tests ◂
Discovered: 07/01/2025
Category: security


Cyber Security Categories
Google Dorks Database
Exploits Vulnerability
Exploit Shellcodes

CVE List
Tools/Apps
News/Aarticles

Phishing Database
Deepfake Detection
Trends/Statistics & Live Infos



Tags:
Dont Count Out Active Directory For Cloudy Future