project database

How To Expire Active Directory Security Groups

There was a question over on Mark Minasi’s Active Directory forum on how to find unused Active Directory security groups.  The answer quickly came that it is “a pretty hard problem to solve for real.”  There are a few vendors that can offer reports/tools that show what file system permissions are associated with each group.  But…

project database

Manage Active Directory On Premise; Outsource Exchange To BPOS

You still need Active Directory even though you have outsourced Exchange to Microsoft BPOS.  So, how do you manage it?  You want your user attributes to be accurate, group memberships up to date, unused groups expired, and security groups to be, well, secure.  Oh, and you really don’t want to have your IT department to…

project database

Leverage Dynamic Active Directory Groups to Avoid Insider Threats

Am I the only one who has been seeing a lot in the press recently about privileged users and the tools and solutions focused on them? When I read this article on insider threats in Network World, I realized that dynamic user provisioning, which Imanami has been offering our clients for years, is a fundamental…

project database

Self-Service Active Directory Update using SharePoint 2010

There is a lot of excitement surrounding the release of SharePoint 2010, and justifiably so. Many of our clients are using it and achieving some great things. That is part of the reason we have made it so easy for GroupID Self Service to be implemented as a WebPart. One of the new things that…

project database

Web Interface for Active Directory: For User or Admin?

Active Directory comes with an interface: ADUC.  It is very useful for admins and only admins.  We have had customers admit to us in the past that they have allowed ordinary end users access to ADUC; this changed quickly once they got a good web based Active Directory self service solution like GroupID Self Service.…

project database

The Best Way to Manage Active Directory Groups

I kid.  All your group do not belong to us.  We just have the best way to help you manage your Active Directory groups with Imanami’s GroupID. We are currently in the midst of our best quarter ever and I have photoshop and I’ve always wanted to make that image.  I’ll probably print up some…

project database

Active Directory Roles and Security Groups

Many of our customers use Role-based Access Control (RBAC). At least that’s what they are telling us. But our products don’t actually support the traditional concept of roles, where you create the perfect role of a salesperson and assign permissions and access to that role. Our customers are getting more granular than that. It’s almost…

project database

How to Avoid Flaws in Identity Management

David Bell wrote an interesting piece in Secure Computing on how to avoid flaws in Identity Management.  The part that I really liked was how he pointed out that the IT security industry is focusing its efforts on “where” enterprises keep their critical data instead of “who” has access to it. It is this “who”…

project database

Benefit Of Dynamic AD Groups – Restore Group Membership

I’m listening to an interesting webinar about backing up and recovering Active Directory.  They make a lot of great points about why to buy a third party tool instead of relying on built in free tools.  I’m sure they’re right but one of the things that caught my attention is that the built in free…

project database

Group Management – How HR can use Existing IT solutions

Our blog usually addresses a technical audience, but this time my message is a bit more focused on one of the business units that IT supports. Human Resources and IT can and should work together.  As I have written before, the roles of the organizations are somewhat similar, and they often must work together. What…