• IAM in Teams
  • IAM Hybrid
  • References
  • Company
FirstAttributeFirstAttribute
FirstAttributeFirstAttribute
  • IAM in Teams
    • Master your Teams Resources
    • Centralized M365 Identity Management
  • IAM Hybrid
    • Single Point of Access
    • Split the Admin Load
  • References
    • Our customers
    • Our projects
    • Partnership
    • Press
  • Company
    • About us
    • Career
    • News
    • Contact
  • English
    • German

Helpdesk and automated groups in AD

Aug 17, 2021 (Letztes Update) | News |

 

Group management and especially security group management is an important part in Rights Access Management. Big companies and distributed organizations have to deal with a huge number of groups an permissions. These enterprises often have local IT coordinators to support daily adminstration and standard issues. Unfortunately permission management is still troublesome.

You could

  1. Completly delegate AD user management
  2. Delegate automated group management only

Our customer, a company with 12 branches, decided for the second option. The company does the main user management in the headquarter. User objects are created by the HR department staff. An Identity Management sync solution pushes them to AD and updates most necessary attributes. But then it comes to permission management.

Admin delegates dynamic groups to helpdesks - Admin view

Permission Management: Helpdesk and automated security groups

The attribute for department is used for a self-updating department group. DynamicGroup provides an easy Query Builder to create attribute based groups.
The customer executes most standard and global permissions by the headquarter IT department.

But there are a lot of small companies that have been acquired by the customer in the last years as well. 

These branches have local IT staff that takes care of special and local permissions as OU admins. They maintain specific permissions by themselves.

Local helpdesk and group automation

One example was a branch with a machine where people got access to via AD group permission.
This machine was only available to people with a certain value in their extensionAttribute5.
The local IT could create a security group with self-updating group memberships that added all users to that group, if they had extensionAttribute5 filled with “access_granted”

Dynamic Group Delegation  

DynamicGroup Delegation

DynamicGroup can be used by “full” admins and delegates.

This enables distributed helpdesks or local IT departments to maintain automatic security groups in their OU.

For more detailled information about the software solution, please visit the product page of DynamicGroup

 

Artikel erstellt am: 21.04.2020
Share

You also might be interested in

FirstWare DynamicGroup 2018

Dec 1, 2018

FirstWare DynamicGroup 2018 creates dynamic groups by itself. The new[...]

Bi-directional organization of Microsoft Teams by IT and employees

May 11, 2022

Time and again, companies contact us describing a similar situation:[...]

EU data boundary for Microsoft cloud solutions – This is the current status

Dec 8, 2021

Microsoft promises that the data of customers from the European[...]

Wissen

Last articles

  • my-IAM PeopleConnect Release – Better search for contacts in Teams
  • Bi-directional organization of Microsoft Teams by IT and employees
  • FirstAttribute – Most popular IT innovation 2021
  • FirstWare IDM-Portal – Release 2020.4 with stronger performance for large enterprises
  • Log4Shell – FirstAttribute software solutions not affected

Categories

  • Concepts
  • DynamicGroup
  • IDM-Portal
  • my-IAM
  • News
  • Projects

LINKS

my-IAM - M365 Self Service

FirstWare -IDM-Portal

FirstWare - DynamicGroup

FirstAttribute – Tech Blog

Contact Info

  • FirstAttribute AG
  • Am Büchele 18, 86928 Hofstetten, Germany
  • +49 89 215 442 40
  • https://www.firstattribute.com

Topics

  • Legal Information
  • Privacy Policy

Latest News

  • my-IAM PeopleConnect Release – Better search for contacts in Teams
  • Bi-directional organization of Microsoft Teams by IT and employees
  • FirstAttribute – Most popular IT innovation 2021
  • FirstWare IDM-Portal – Release 2020.4 with stronger performance for large enterprises
  • Log4Shell – FirstAttribute software solutions not affected

Siegel FirstAttribute

© 2022 · FirstAttribute AG.

  • Legal Information
  • Privacy Policy
Prev Next