Modern enterprises run on directory services like Active Directory, but that same centralization creates a dangerous single point of failure. Direct, always-on access to the directory turns compromised credentials into a launchpad for lateral movement. Restricting and mediating that access is critical to limiting blast radius and preventing attackers from moving freely across environments.
Nitish Deshpande, Senior Analyst at KuppingerCole Analysts, provides an independent perspective on evolving identity security challenges. He discusses why native directory tools are no longer sufficient to protect against modern attack techniques, explores how unrestricted administrative access amplifies risk, and outlines strategic approaches to minimizing lateral movement. He also explains how modern identity architectures and access mediation align with Zero Trust principles.
Robert Kraczek, Global Strategist at One Identity, dives into practical implementations of air‑gapped directory access using an architectural approach that restricts direct interaction with the directory itself. He shows how solutions such as Active Roles enable fine‑grained delegation to tightly control administrative access, apply automation to enforce joiner/mover/leaver workflows consistently, and ensure identity changes are executed immediately and securely. Through real‑world use cases, he demonstrates how organizations can reduce lateral movement risk while maintaining operational efficiency.
Who Should Attend
This webinar is ideal for IT security professionals, identity architects, and infrastructure leaders responsible for protecting enterprise environments. It is particularly relevant for those managing Microsoft‑based identity ecosystems.
Hello, everyone, and welcome to today's webinar, Stopping Lateral Movement with Air Gapped Directory Access. My name is Nitish Deshpande. I'm a Senior Analyst at KuppingerCole Analysts, and today I'm joined by Robert Kraczek, who is a Global Strategist at One Identity.
Hi, Robert. Welcome to the webinar.
Hi, Nitish. Thanks for having me on.
Hello, everybody in the virtual audience. Glad to be here. Perfect. Thank you so much, Robert. Looking forward to today's conversation. It's a bit of a different style of webinar we are having today. It's less slides, more about discussing ideas and conversations, so it should be an interesting one. But before we begin, just a quick, I can say housekeeping rules here. So you all are simply muted, and we are controlling these features from here.
As always, we try to have these webinars a bit interactive, so we'll be running a couple of polls during this webinar, so I'll encourage everyone participating in today's webinar, attending today's webinar, to take part in these polls and provide your answers. We will discuss the results of this poll towards the webinar, which is the Q&A session. But if you have any questions during the webinar, you can enter them at any point using the Livestorm Control Panel.
And finally, we are recording these slides, recording this webinar, so you'll have the recording of the webinar and the slides ready for download in the coming days on our website at topingrecord.com. Before we begin, I would like to just, let's just start with the first poll of today's webinar. And it's a really interesting poll, and I'd like to understand what our audience thinks about it, is that what's currently standing between your organization and removing standing admin access to Active Directory?
Is it, A, operational dependency, where too many processes still rely on standing access to function? Is it, B, a lack of tooling, there's no mediation layer in place to delegate or automate access?
Is it, C, lack of executive buy-in, market position as a risk priority at the leadership level? Or is it, D, you haven't assessed it yet, you don't currently have visibility into who holds the standing access? So the poll is live in the Control Panel, you can select your options, and we look forward to discussing the results towards the end of the session. And I think with that, Robert, I would like to open the floor and start with you first to maybe set this up for understanding a bit more about this topic.
It's an interesting topic, and maybe start with just the first one is where does a lateral movement usually begin, and what remains a major risk in this area? So based on your conversations with your customers and the work that you have done, where do you see this lateral movement usually begin, and what is usually compromised? So that's a really interesting question, and as I was reading the poll, I'm thinking, what would Rob Krajec from 2003 think about that poll versus today? And it's surprising how many people still have lateral movement issues with Active Directory in today's environment.
So my thoughts on it are kind of mixed and complex. I used to be an IT admin, and I was an IT director for a big hospital, and we had the first versions of Active Directory. And when we implemented it, it was just used as a simple user repository with very basic authentication methodology, and it was a security hole.
I mean, I don't know if you remember this old joke. The old joke was the most secure Active Directory environment is the one where the network cable is unplugged from the back of the machine. But of course, now we have Wi-Fi, so that joke's old. But to answer your question, I would say it starts with your domain sprawl and how you're managing that on-premise footprint.
I find in environments both large and small, but mostly in large environments, there's a lot of segmentation that happens from a management perspective, and some people don't know what was performed in that environment before they inherited it, so they don't know where that actual risk exposure is.
So the lateral movement could be an expired non-human identity service account or something that's not being used, but still has too much access, or it could be someone with too many domain privileges because, you know, whoever was administering the environment just said, I don't know how many rights you need, so I'm just giving you everything. Good luck. So to answer your question, it varies, right? It varies on the the awareness you have of your environment. It also varies on whether or not it was properly designed in the first place. What do you think?
It aligns with you as what I think as well is it's kind of the, you can say, the bridge between your initial compromise to your business impact, if you go on that level as well. So the real question is that if one credential is compromised, how far can the attacker go? So it starts with, let's say, one endpoint, one user, one password, but it can quickly snowball into something much bigger. So I think lateral movement is a major risk right now, and so I agree with the points where you mentioned that it begins as well.
And it's also sometimes difficult to stop, even when you have some tools like MFA or endpoint security as well. So it does secure the entry points, but it does not completely eliminate the privileged parts or it does not see the exact attack surface. So maybe what do you think of these tools as well? Are these tools sufficient or there needs to be something else in there that can be working to help this?
Well, I have some interesting statistics I'll bring up that we can talk about. Let me just share real quickly. So to answer your question, you know, the native tools themselves, I think, are fine for administration, but they're really not a mitigation tool set. They're really there for the day-to-day operations of that directory service, which you guys have rightfully identified in your line of business survey as a line of business application. Because going back to my analogy of where we were back then versus where we are now, I'll skip to this slide real quick.
You know, to answer your question, I think that the tools are good for administration. They're bad for analyzing risk and understanding the overall risk that that user account in Active Directory actually poses, right?
So, you know, you can do group policies and you can do other things to try and mitigate the blast radius, but you're really not thinking about it from a big picture view. So I think native tools are fine for what they are, but you definitely can't understand the big picture or the big risk exposure from, you know, this graphic. I have a very simple thing of, you know, clouded on-premise apps. When Active Directory was first adopted, there were no cloud apps. They didn't exist, right? You were literally doing on-premise workstation type stuff.
So understanding the blast radius now yet and mitigating that with native tools, they weren't designed for cloud app awareness. They were designed for adding things to groups, right? So I think that they're very deficient in that area. And that's why you see so many breaches in the Active Directory space, even today, because there's no awareness there. You have to attach other solutions to that footprint.
Yeah, I think that's why also this Active Directory is very important for this discussion as well. From other point of view as well, if we talk about other IAM models, like maybe IGA as well, when we do the evaluation of IGA solutions, one of the first questions we try to understand from the vendors is that, do they provide support for AD for functions like identity repositories and addressing those things, the contextual attributes from there. So that's why I think the Active Directory is quite important for this discussion as well.
It often goes from who controls Active Directory that can control access. So that's why it should not be a direct broad access, but there should be some sort of something in there and some sort of layer in there to limit that access. So I think it looks great from here.
Yeah, and I wanted to ask you, so you've obviously, I've filled out a lot of your surveys, and particularly the PAM and IGA surveys. Those are the surveys that you're responsible for. Where do you draw the line between IGA and a solution where you're managing AD? Do you blur them together or do you think there should be a line of delineation, particularly in the PAM? In the PAM survey, you have to take a lot of systems into account, but do you think that Active Directory accounts should be more granularly controlled than what you can do with a traditional PAM solution?
I know this is a real question, but yeah. Yeah, I think, first of all, I appreciate you filling out all those questions that we sent you. I know sometimes they can be a lot, but yeah. Can you talk about drawing the line between, let's say, what's a good enough native Microsoft tooling?
I think if we maybe, I've had this conversation as well, is that there's this gap in the market around for companies that have around 500, 2000 users, and that the organizations require more than just native tools, but they're not really ready for the full-scale IGA deployment models for the obvious reasons, such as it's complex, it's expensive. So there's this gap in the market which can be addressed to something like a governance layer for the Microsoft tools.
And so, while native tooling may be enough for the configuration, I guess, sort of a mediation layer is becoming important for such kind of organizations. I think that the line is usually crossed when you go into much more complex environments. So there's the other side as well.
I think, or I think that's, to answer your question, I think that's maybe the line that we have. Yeah, when I did, when I worked for a big four and I did implementations in the cyberspace, one thing I noticed was you had a lot of large organizations that would have, let's say, an IGA tool, and they would attempt to manage dozens of the Active Directory domains as part of their governance strategy. And they were always struggling with trying to restrict access, but still grant access through the IGA tool.
Because as you know, you know, typically an Active Directory connector through an IGA tool, you have to do a point to point to point, you know, that can be federated. You could have multiple federated into that particular connector instance, but you typically have to do a separate connector instance for each domain or each grouping of domains. And that's why I've seen, you know, as an advisory person that that typically never got implemented correctly.
Frankly, I mean, it was because people would realize, oh, Active Directory isn't a simple connection, we actually have to do a lot of attribute mappings. And then, oh, now we have a dozen that were at separate attribute footprints based on when they were installed and what kind of services they provide. So I found that there definitely, I agree with you, there's definitely a gap in IGA managing multiple ADs and what is needed. So obviously, you could design, you know, something through customization and services. But like I said, I've never seen anybody actually complete it. Yeah.
And the other thing is, as these environments are sprawling, lots of issues around that. So the market, what we're seeing right now is moving towards a bit more, that is granular, policy driven, contextual, context-aware delegation. So at the end, organizations want some sort of control or at least a crucial and not just over the rights of a group, you can say. That's right. Yeah. And that's another thing you have to think about is delegation, at least privilege principles, particularly in today's NHI landscape, right? Agenic AI hit our industry by storm.
Now we have people, who teams that typically wouldn't work together, now they're all concerned about this access to agenic AI and this kind of dark, not dark web, but you know, shadow IT that's going on where people are, you know, put using cloud on their machine to, you know, to do API calls that they shouldn't be doing probably. But I think that, you know, we're seeing teams that typically just discounted Active Directory as, you know, just another directory service that they didn't really care about.
Now they're worried about it because of the whole agenic AI and NHI process that's, that we're going through now as an industry. Yeah, it's definitely the topic. It was a topic at the EIC conference in Berlin one month ago, when I was there. The industry is, I guess, embracing the change that is coming with NHIs and AI agents. We have several new ideas coming around that from different vendors.
I think the organizations as well as realizing that once you show that, once they're seeing the picture, how many of these NHIs they have in their environment compared to humanities, then I guess it's becoming much more clear why it is important right now to address this issue. Yeah, it goes back to, you know, so the earlier comment about, you know, the age of some of these Active Directory environments, there are service accounts in there, nobody knows what they do. I can guarantee it.
I guarantee everybody in this audience probably has an environment where they're like, I don't know what it does, but it's continuing to do it. And I don't want to change the passwords or anything. But that's a risk exposure. And typically, if you start exposing some of these smarter, you know, ML, machine learning and AI systems to that environment, they might discover ways of getting into data points that you didn't know were there. I many times as a consultant, I would go back to a client that I haven't seen in years and log in, and I had the exact same access I did before I left.
So and that's for through service accounts and scripts and things like that. So it's definitely a reality. And I think a lot of you are probably laughing or agreeing with me that that's still the case in our world. So that was the challenges of which I also saw in speaking with several of these NHI vendors is that especially for these orphaned accounts, the associated NHIs were still active. So that again, let's say increased the attack surface as well.
Yeah, and I think it goes beyond that. I mean, obviously, we all have users that we maintain or administer in our environment that started out with AD and they have access to other things like SAP systems and, you know, cloud systems, and they're federated to a third party. But all that access, that authentication, that initial authentication starts with typically with Active Directory even today, or a federated intra AD environment. And I find that they very, very rarely have only the access they need. There's always some sort of sprawl, some sort of lateral loop.
They have some privilege somewhere. And that goes beyond or is a little nuanced beyond what you would typically do, you know, requesting access to a privileged password through a PAM solution or a privileged session. It's usually they have a little bit too much access in this group, or they're in an empty group, there's only them in there. And it has all this access because somebody gave up five years ago trying to balance it. So a lot of sprawl.
So the other thing I wanted to ask you was, so now that we, you know, when you look at frameworks, security frameworks, where do you see Active Directory as a management point for those? So, you know, NIST, CISA, Zero Trust, you know, even as far as GDPR, there's lots of different ways to slice and dice directory access. But if you could summarize, you know, directory access governance, are there clear requirements and a lot of these standards for how you should be managing your directory access? Or is it pretty loose?
It's, we have some leadership composites around that, for example, the Zero Trust ones, which we dive much deeper into that. But on the leadership composites for IGA, which I've been doing for a while now, we try to understand if the vendors have compliance for NIST. If they are, if they're also, you know, have a registration for SOC type two or some certifications as well. So that is in our criteria to understand what is the, you can say, standard support of each vendor when we are doing that.
And that is also important to, from the security point of view as well, when we're checking the product as well. So that's, you can say, the current evaluation limit for these kind of compliance frameworks. But we do also have another additional way that we try to evaluate this one, evaluate is that we're trying to understand if the vendor supports different compliance framework for the auditing and reporting format.
So we dive a bit deeper into that because auditing, reporting, compliance for us, when we decide what an IGA solution should have, this is one of the critical areas, apart from your lifecycle management, access governance, SOD as well. So that's a critical part of our IGA leadership responsibility. So do you think directory access governance is, well, so directory access governance is essentially, I think, a subset of overall, you know, IGA, right?
The G, the governance part, is where you're administering how people are getting access to that directory footprint. And then from there, what do you do? So you have your standard entitlements, you have policies attached, you have prime role, well, policies attached to roles. So when you have birthright entitlements or somebody's added to a role, you get this directory access. Do you think IGA tools do enough by themselves? I know we talked about this from a connector perspective.
Do you think they do enough by themselves to understand the overall risk posture of an identity inside of Active Directory? Or do you think that they give a, that they're a broad stroke solution, and that, like you said, there's that gap?
Yes, I think it's, there is, let's say, a missing layer, that we can say a mediation layer, which could work for, like, you can say, dissecting this directory access governance. Right now, with IGA, we have, you know, they provide quite a big set of capabilities, I guess, solutions that are behind the market right now.
It's, the core capabilities are mainly just around provisioning, certification, reviews, SREs. But if you go a bit more deeper into just addressing the directory, and that's where maybe the, something like, I guess, an active role, I guess, makes sense to have it.
Well, thanks for the plug. I appreciate that.
But, yeah, so the way I look at it is this. So, you know, I haven't been a practitioner for a long time. I look at something like an SAP connector. So we have one that goes deep into the, you know, the S4 and R3 security and R3 security model.
I mean, it goes way in there. That's the kind of stuff I think you need, if you were to have an active directory connector in IGA, you'd want to see. But what I typically see in an AD connector, including our own, is we have, we do attribute mappings, we can do, we can suck in groups, we can look at entitlements, and then we're, we're done. Right? There's a lot of extra scripting of these that happen to go, if you wanted to do, like, delegation and least privilege type principles, you really got to understand the model and then build it.
So I think, you know, like you said, with our active roles product, it's essentially the deep level connector into that security model of active directory, very similar how we access, you know, we would access SAP through our SAP connector. So I think there is a need for these types of things. I'll actually show the audience a little bit of it later.
But, you know, I think from a and back to the security standards perspective, I think that they're viewing active directory as a line of business application is a very healthy thing you should do. You shouldn't view it as a utility. I think it's, it's so important and intrinsic to every organization, even if you're moving to the cloud and getting out of it, you still have so many on prem systems, other things that access AD, you need to think about it from a governance and business perspective, not just as a tool. So I'll give you an example. So you'll laugh at this one.
I was talking to a customer, I won't tell you who it is. And I was in a virtual boardroom. So we had the CISO at the head of the table, and we had four or five people on either side. And I was supposed to go up next. But the first thing that happened was he had a, their cloud architect stood up and he said, we're moving to intro, we're getting rid of AD. He just made this announcement. And everybody just kind of looked at him. And the networking guy stood up. And he said, that's great. But all of our Palo Alto equipment uses AD for authentication. So what are you going to do about that?
So what do you think, Natasha, do you think that that's just a limited, that's just an isolated gap? Or do you think there's a lot of dependencies that people don't know about that they're using Active Directory for?
Yeah, there is definitely that gap in there is understanding the real use cases of that. I think a good example to share with us right now, and that slightly highlights, let's say the discussions that are happening around it. But maybe when you're also talking about something like, you know, Active Directory or maybe lateral movement. So we talked about some of the things like lateral movement, but sometimes when it can be difficult to differentiate what is a legitimate movement and what is not.
So are there any signals which you which you have come across that can be used to identify it's an illegitimate lateral movement happening here? Yeah, so sorry, I skipped over a slide here.
But so, you know, when you when we look at we look at Active Directory footprint today versus what it was, like I said, two decades ago, I see a very, I consider it like layers of an onion. So those in the audience to think about an onion, right? You start the onion starts very small, then it keeps growing more and more and more layers on it. And most at 80 environments, and I'd be curious if anybody has any comments in the in the audience. How old you're a I should have had that as a poll. How old is your Active Directory environment?
Because I can almost guarantee that nobody has a brand new fresh one. They've been there for a long time. So do you think as a, you know, in your opinion, that these these ad environments that are very layered and have a lot of nuance? Do you think that they pose an inherent risk to the organization? Or do you think it's just a passive risk, and you don't really need to be as concerned as you would say, an application that's exposed to the internet? I think it is.
Yeah, I think when we can ask the audience as well if they have anything to say in this one. But I think, as I mentioned earlier, is that when we support an IG solution, something like an Active Directory works as the foundation plane for all the contextual things. So it is very critical. And I think that's why it's very important we include the discussion of Active Directory and this lateral movement as well. Yeah. Yeah.
So, you know, lateral movement to me is an interesting one from the perspective of all the federation that we see today in today's modern environment. So you're granting access to a lot of external entities through, you know, even through an IDP, they're eventually going to come down through Active Directory to get somewhere. But I also see it in my travels, I see it in bridging. So there's a lot of AD bridging solutions.
One identity has one as well, where people are taking Unix and Linux or even Macs, and they're bridging that account, that identity record, or that identity information, and they're bridging it into AD so that they can do things, you know, from a centrally managed perspective.
So now, you know, we did have lateral movement between Windows devices, and, you know, things that are AD native, but now you can potentially have lateral movement into these Unix's and Linux's, particularly if you don't secure them with some sort of sudo replacement or some other methodology, they could just slipstream right into a system that typically wouldn't have been exposed to that type of risk before.
So I'm wondering if we've introduced, by trying to simplify things for people, we've introduced more risk than we had in the past, because we're able to bridge these other types of directories into AD. So I don't know if that's a valid concern or not.
I mean, what's your opinion on that? Do you think that bridging it while it simplifies things might introduce even more lateral movement? Or do you think that the problem is pretty much solved? We need to maybe have some sort of lateral movement defenses in place to have regular checks on that. But it might simplify things, rather than making it more complicated. It would be interesting to see what our audience also thinks on this.
Yeah, because that's a separate thing from even IGA, which I know is your, you know, what you specialize in. IGA is a very broad stroke, you know, type of, you know, join or move a lever and governance on top. But then you, like you said earlier in the session, you know, native tools plus things attached to the side.
Well, that bridging technology is attached to the side, right? That's something that people attach to get to another destination, as well as, you know, tying in, you know, I talked to, I saw, or I met someone the other day at a trade show, they use AD LDS for everything. I didn't know anybody still used AD LDS. So that was fascinating to me.
But, you know, that's a lightweight directory service that's based on AD that also has risk exposure as part of its potential, you know, footprint. So there's a lot of things that are on premise today that are AD related and adjacent to AD that I think our audience and our discipline in general don't take into consideration as a business problem, they think of it as a technology.
And I think that, you know, air gapping that, you know, air gapping those directories from the administrator or from the people that could potentially do harm is a good thing, regardless of whether, you know, what IGA or other tooling you have, separating those two and creating at least a buffer is, you know, is a great way to at least mitigate risk, if not eliminate it. Exactly. I think the admin should get the action they need and not go that's overall broad access of everything around. So I think this also maybe aligns with the, you mentioned earlier on zero trust principles.
It's always trust, never verify. So I think this aligns with that too.
Yeah, so I know we got it. Now you got me curious. So zero trust, do you think zero trust, I'm going to ask you a hot, I want a hot take from you. Is zero trust real? Will it ever be achieved? That is the question we all trying to answer.
Yes, it is. It's a long process. We all are working towards that.
Yeah, I think it can be achieved. I'm optimistic. I think our industry has a lot of great technology. I also think that with the advent of AI, if used properly can help you achieve that. Some people disagree with me. I think that, you know, using these AI models to achieve zero trust is possible if you allow it to analyze your comprehensive IAM program and then make recommendations along with, of course, humans that know what they're doing. But I think zero trust can be achieved. I think that air gapping your AD is part of that.
I also think that the, you know, starting with the least privileged model is a little bit simpler to do. Because, you know, zero trust, you're essentially yanking the carpet off from underneath everybody and then, you know, making a very dynamic environment that you want to, that you allow, want people to utilize on demand, right?
So that's, that's the broad strokes of zero trust. I think least privilege in the context of air gapping AD is a great place to start because it's a, it's a known technology. And I think least privilege is a lot more attainable for today's tooling and today's overworked IT folks. I have another question for you. Have you met any IT teams in your advisory capacity that said they had too much staff and they didn't, they, they didn't have enough work? Okay.
It's the opposite that I've seen is that when we tried to ask what is the main challenge they faced in front of their IAM project, stalling or failing, and the most common answer was lack of, let's say, skill shortage. So they did not have the right enough people, I guess. So it can be, so there's demand for that. Yeah. Same for me. I actually hosted an event where we drove supercars and I couldn't get enough people to come because they were all working. So if that tells you anything, who doesn't want to drive a Ferrari? That should be another poll question, right?
So yeah, I think, you know you know, this is a good conversation. I think the least privileged model starting with something like a line of business application like AD is a great place to start because it's a known technology. It's a known problem and air gapping it is relatively simple depending on your model and how you implement those models.
And I, you know, where does that sit in the prioritization for an IGA program? Because I, you know, I've seen, like I said earlier in the session, I've seen people take the AD, once they realize the AD task is a little harder than they thought, they deprioritize it lower and, you know, only set, they set lower bars on the target systems they're going to attach to from an AD perspective and how they're going to organize it. Do you think that, you know, in an overall IGA program that's the case?
Do you think that clients are going to start elevating where they place AD in their implementation instead of phase two? Maybe it's phase one or maybe it's, you know, always been phase one. What's your opinion?
Yeah, I think it will be prioritized, definitely. What we are seeing as well is the increasing focus on SaaS and Microsoft ecosystem governance.
So, having a layer which for managing entitlements and sprawl and also this shadow IT within the Microsoft environments will be recommended as well. Yeah.
Yeah, shadow IT, that's a term that keeps coming up and I think that that's a, I think we've used that for in our industry for a very long time because, you know, IT folks are inherently curious and we're always willing to adopt new technology and I think we'll adopt the technology before we recreate the controls and governance around it. That's usually the way it goes.
So, again, I think that, you know, Active Director being one of the line of business building blocks of your environment, today, you know, even still, is something that you consider when you're snipping out the shadow IT, when you're using, when you have an ITDR program or if you're using other external detection methodologies, look at your AD, really look at it hard and understand where, what's happening with it, because if you're, I think there's a, there's a diagram I don't have in my deck, but where it's a bunch of technologies and then there's just one little stick holding the whole thing up.
I think you've seen that one too. And that stick in this case, in this, the context of this conversation would be Active Directory. If that breaks, it all topples over.
So, I think, yeah, this is maybe, again, a good time to introduce our second poll of today's webinar and ask our audience what, which layer would you trust least to stop a compromised admin credential from reaching AD? Is it A, native Active Directory permissions, so you have your OU and group-based delegation that assumes the admin is already trustworthy?
Is it B, the PAM vaulting alone, secure checkout, but doesn't restrict what's possible once the credential is checked out? Zero trust policy, documented as a direction, but not enforced, let's say, at the directory layer? Or is it D, not sure, so you haven't mapped which layer would actually stop lateral movement?
So, this poll is, again, live in our control panel. You can, audience can go and select the right options and we can discuss those poll designs very soon in a few minutes.
So, again, handing it back to you, Robert. Oh, thank you.
Yeah, I'm looking forward to seeing the results of these polls. I'm always curious to see what my fellow practitioners are doing with their technologies and where they are in their day-to-day lives, because I know we all have a lot of technologies we work with every day and, you know, Active Directory is just one of them.
So, I think the last thing I'll do, and we could have further conversation, like we still have plenty of time, but, you know, we've covered standards, we've covered, you know, mediation, we've covered, you know, lateral movement and air gapping. I thought I'd show the audience just a quick commercial of what Identity offers, and then maybe we could, if we have a little time, we can take questions from the audience and see what they want to ask us. One identity provides a product called Active Roles.
Active Roles is an Active Directory administration and governance tool that provides capabilities for air gapping your Active Directory environment, aggregating Active Directory into a single point of administration, and I think most importantly, as part of that air gap process, it allows you to delegate and obfuscate or remove the native tool access from folks that don't need it, while still allowing them to do their administrative or governance tasks instead of AD. So, let me give you an example before I show the quick video. We have a customer that has 200 domains under governance.
I'm sorry, 203,000 users, 83 domains. They do it through one tool and one administrative portal.
Now, obviously, they have delegated administrative access so that the administrators responsible for those specific business units still can do their jobs, but everything's audited and tracked centrally, and that's the key, I think, that Natasha and I were talking about was, you know, where does IGA stop and where does this type of tooling begin, and I think if, you know, regardless of where you are in your journey, if you could find tooling like Active Roles that allow you to aggregate these domains into a central point and then possibly provide that feed to your IGA tool for broader governance, you'll be able to reduce the footprint you have maybe through Active Directory connectors and try to manage everything separately.
So, this is just a perspective. I just wanted to point that out that we do provide that. I'm going to show you just a quick 30-second video on how this thing works, and, of course, we'll provide more collateral after the session. From a security perspective, think of Active Roles as privileged access management for AD and Azure AD.
It allows you to truly delegate a least-privileged access model where highly granular permissions can be applied to objects, not just by organizational unit, but based on any criteria you can imagine, ensuring that your users only have the exact access they need and nothing more. You can control the process of creating, managing, deprovisioning, and restoring objects by enforcing policies to require that your environment adheres to your data standards, audit controls, and business needs.
So, that's just a quick little commercial on what we offer. Active Roles is used by very large organizations for aggregating Active Directory as well as for basic administration and delegated administration. I find it very useful for the clients that I talk to. Even before I came to One Identity, I actually implemented it a few times as part of a project or saw folks use it, and I was very curious about how it worked.
I think to summarize the capabilities of this particular solution, Active Roles, it aggregates AD, it allows you to delegate administrative privileges, and it allows you to create a cleaner pipeline into a broader IAM or IGA program. It sort of acts like a PAM solution too, but obviously that's a gap that a lot of folks have in their IAM program. Some of you may not need it if you're a smaller single domain environment, but I would still encourage you to take a look at these types of tools like Active Roles as that gap, that air gap methodology between IGA and native tooling.
Because as we, you know, as NHIs become more of an issue, and they are quite an issue now, and you have things like OT management where you want to kind of distance the OT app platform from the general population, this is a great way to do that. I have very large customers that use Active Roles to take Active Directory information from one domain, send it across the wire to another Active Roles instance, and there is no direct IGA connection. They view it as an M&A activity.
So I don't know, Nitesh, I don't want you to put words in your mouth about, you know, where this product fits in the overall picture for Coppinger Coal, but do you think that, you know, air gap, air gapping Active Directory is an important thing to clients, or do you think that it's, you know, it's something that it's nice to have for some, but maybe necessary for only a few? And it's definitely, let's say, aligning with or positioning this as predicated governance admin layer for especially the Microsoft environment, I would say.
It's definitely addressing that gap, which you mentioned earlier, for especially these kind of customers who are in between, let's say, SMBs and maximum 2,000 employees, but they don't want the full IGA solution. So I think its role as, you know, a governance layer for AD, it definitely fits in there. One question you mentioned around, let's say, it's around different types of its support. There's one thing which is quite prominent right now, the topic, it's over around, let's say, EU sovereignty.
Do you think maybe this is also relevant to that, or can this be expanded to meet that requirement? Yeah, so, I'm sorry, I only heard half the question.
Maybe, could you repeat it, please? Yeah, so the question would be just that, is this somehow maybe relevant to, let's say, EU sovereignty? So we have several requests coming around that recently. So would you suggest that's also the case for these active roles?
Yeah, I mean, you could use active roles in that capacity. So if you're talking about setting up your own sovereign environment, you could. So folks have used, folks use active roles, and we have a lot of services partners who use active roles for M&A activities. So what they'll do is they'll they use it to, they'll aggregate, like I mentioned before, they'll aggregate these domains from different business units into a single management portal, but they're not federated, they're not combined.
So if you were to use this, and let's say you wanted to split off a particular international business unit for, and put it in its own sovereign cloud, you can use active roles to administer everything, but you wouldn't have a direct federation that you'd have to break up, right? There wouldn't be trust that you'd have to break, there wouldn't be other relationships that would cause a lot of trouble.
So I would say if you're, if you have separate domains now, and different nations, and you want to manage them over the wire, you know you could do something like zscaler to an active roles instance somewhere, and then that would allow you to aggregate all that network traffic one place, and then let's say you decide to go sovereign cloud with one of those international units, you could just separate that, you could just keep that line separated, just move all that data, you could still even keep the connection to active roles, you're not providing a central repository per se, except for audit information, so it keeps things very flexible, right?
You can move things around very quickly, versus as you know, once you establish a domain trust, or you know, establish a force relationship, it's a lot tighter, it's a lot tighter. So I think that's one of the advantages of active roles, is that you don't have to go through all that baggage that the native tooling requires you to do.
All right, perfect, thank you so much. We just have, let's say, around 14 minutes left, I guess it's a good time to go over the results of the polls. So the first question that we are asked was, which layer would you trust?
No, sorry, that was the second one. First one was, what's currently standing between organization and removing standing admin access to AD? And the option that has received the most votes, that is 38%, is operational dependency, while lack of tooling, and haven't accessed it yet, are at second and third. When you look at this result, Robert, do you think this aligns with what you're also seeing?
Yeah, so I see a lot of, I see a lot of that. You know, I think that the issue that most people have is very basic.
It's, you know, they're just trying to fix their environment. So yeah, this is absolutely what I see with folks that I talk to that don't have this type of tooling already.
Perfect, and the second question was, which layer would you trust least to stop a compromised admin credential from reaching AD? And 64% votes have gone to native AD permissions, while policy, I'm not sure, are tied at 18%. I guess then that's a resounding answer from audience here as well. Do you agree with them? That makes sense.
I mean, native AD permissions, particularly if you have group policies and other things in place that you don't know what they do. So how can you trust something you didn't design or put it in the first place?
You know, I'm sure, Nitesh, you've gone through and edited domain policies and group policies before. You know how complicated that can be, particularly if you have inheritance, because there's no, you know, there's no big mapping that you can really view everything. You've got to like pick through every attribute and make sure that things are flowing correctly and then look at the actual object and see what's inherited, what's direct assigned.
And then, yeah, it's a real hassle. And that's, honestly, that's one of the reasons that the original generator mover lever functions before even governance was part of IJ tools, that was one of the things they were trying to solve is all that inherited rights mapping, but it's still a problem.
So yeah, native AD permissions, I can't imagine. I feel anybody in the audience who inherited a big environment and they don't know where all the permissions are, I feel bad for you because I'm sure it's a real problem.
Okay, thank you. I think we're talking about big environments. We have a question right now. So the statement is my organization needs to run a report against AD to review what accounts we have, who, what has access to what, et cetera, essentially to enable a cleanup of an older AD brownfield estate across 100,000 user people environment. The question is how can active roles help? Can I get reports and visualizations? So if you connect, you didn't say how many domains it is, I'm assuming it's more than one, but maybe it's one.
Once you're connected to active roles, you'll have a, it'll lay out a really nice picture of, you know, a visualization of the domain. And then it also can help you with auditing and tracking the identity, the users and the accounts and other objects inside that domain so that you can get a better view of what you're administering.
Now, if you want to do migrations, there's other tools out there for that. It can help, but it can help you facilitate a cleanup and understanding of what that domain really has in it before you start, you know, doing other activities with it. So absolutely active roles can help with that. If you'd like, I can follow up, you know, we can follow up after I get you a more detailed response on some of the things you've done with other larger customers, but yeah, active roles can help with that by collecting the data and helping you visualize what it looks like. Perfect. Thank you so much, Robert.
The next question we have is if we already use PAM and MFA, do we still indirectly access mediation? I think we slightly touched on this topic at the start of the session.
So yes, mediation layer makes sense in certain cases, definitely. So I think we touched on that.
Yeah, yeah. I think that's a topic that PAM serves a purpose, a very important purpose, but you need another layer in there to understand not just the privilege accounts, but the overall account footprint and how they're being used in this environment. And then you want to obfuscate that native tool layer from the people that don't need to be working the native tools.
If you can centrally manage all that from one place, you know, PAM is there to request passwords, request sessions, go to very specific touch points that allow you to administer, you know, a very secure environment, right, or be doing it a very secure manner. These active roles is a mediation tool and a PAM tool for AD to pull back the native tooling so that, frankly, the privileged account isn't needed as much. If you can create a delegated environment where they only have the correct attributes they need to do their job, then you know what they're doing.
Do they need to request a privileged account to do it? Might not. You might be able to set it up right in active roles. That makes sense. Perfect. Thank you so much. Do we have any more questions in here? So there's, okay, yeah, we have one more question in here. How can we reduce direct AD access without slowing down helpdesk and admin teams?
So yeah, this one more question. Yeah, well, that's a delegated access question and active roles actually provides a helpdesk portal as well. We have customers, a couple large cruise lines that use it for password reset. So they use it along with ID verification so that you, you know, you provide a picture, you provide a, you know, whatever is allowed and then they'll reset the password using active roles portal, the web portal, without having to go into any other tooling. You can even provide a password reset function, you know, for administrators or for anybody else very quickly.
So you don't have to go into a native tool and do it all or, or get another product that just does password resets. So yeah, it helps streamline things. We do it for cruise lines. We do it for a number of different companies. Perfect. Thank you so much. Do we have any more questions from the audience? We have addressed most of the questions right now. Maybe one question from me to you, Robert, is that we got some responses in the poll question saying that they haven't assisted yet or they're not sure for such organization companies, where should they start right now?
Well, I mean, starting at the beginning. So, you know, when you, when you look at your, your, your footprint, if you don't have a full awareness of, you know, your domain footprint and what people have built in the past, the first thing you need to do is you need to audit it. So I would recommend, you know, you could use active roles, you could connect it to your domains, and they can start collecting data. Don't change anything. Just let it figure out who's touching what. And then from there, you can figure out your inheritance model, and then integrate it into an overall IGA program, right?
So once you go from the ID footprint, and you understand you have it connected, you're collecting data on the users, the groups, the organizations that you have in that, I'm assuming multiple domain footprint, then you can take that data, you can work to clean it up, and then you can feed it into an IGA program to establish a broader governance perspective on entitlements and other things that people are inheriting from other sources of truth like HR or, you know, people saw our service now or whatever. So that's, that's where I'd start.
I'd start with assessing what you have and understanding other trust relationships, how many users are actually either are there groups that only have one user, that sort of thing. So that's my recommendation. Perfect. Thank you so much, Robert. I think hopefully that on that gives a good direction for those who haven't started yet. Do you have any maybe closing statements? We're just towards the end of the webinar. Any final recommendations?
Yeah, I mean, if I were to put my advisory hat back on, I would say understand what you don't know, especially in your identity footprint. Today's world is changing very fast, andogenic AI is going to make it even faster. So siloed environments where you have different teams operating under different security principles is not going to stand going forward.
I think we're going to see more and more of a blurring of a gap between these different departments and line of business applications like AD, understood from a from a business perspective, because I can tell you boards right now, they, they workshop a breach at their level. Now, I would say that was unheard of 10-15 years ago.
Today, there's so many penalties around filing standards. There's so many ways that you can get breached. You need to understand these basic line of business applications like AD and understand where they sit in your environment and how they're being used. Because it's become a governance, business governance imperative, not just a technical problem. Perfect. Thank you so much, Robert. I agree with you as well.
The thing, the takeaway is that network movement is, it's there, it's not a, it's not only network problem. So it's also identity problem. And if direct AD access is broad, it should be avoided. It should have mediation there in between. So perfect. Thank you so much, Robert. If anyone has any, any more questions, you can connect to us offline. And thank you for joining and look forward to seeing you at the next webinar.
Thank you, Robert. Thanks, everybody.
See All Locations
See All Locations