Thank you very much. Welcome everybody to the presentation on B2B identities. Maybe some of you are asking, okay, still a topic.
Yeah, we were talking to our business units and they said it matters. And so we said, okay, let's take a look and follow the golden rule, listen to your business. And so let's see how can we make it more efficient by automation and this was automated and accelerate it fast. Okay. Another one. Thank you very much. Good. Now you can see the title. Good. A brief introduction on Boehringer-Ingelheim. Boehringer-Ingelheim is a family-owned pharmaceutical company founded already quite some years ago, roughly 140 years. Ingelheim is located a bit away from Frankfurt in Germany.
They are the headquarters located. The focus is on human pharma, but also animal health and Boehringer-Ingelheim is doing a lot of research and development to bring up new pharmaceuticals and coming up with new therapies to help the patients. You can see this quite some expense in R&D and also having a lot of sites where we're doing this stuff.
So I had also the chance to join Boehringer-Ingelheim doing my studies in information technology and during that time I already got into the topic of identity management and by that I could now gain more than 20 years of experience in that topic with Boehringer-Ingelheim. Currently I'm acting as the enterprise process owner for identity management and having this long history already, I can also get into the overall history. Here we go. So it started already around the end of the 90s and had a very funny today, sounds very funny starting point, cleanup of NT4 domains.
But you can see already at that time there was the question which identity owns which accounts and I can imagine especially at that time having many different local things, that cleanup was an important thing to move to Active Directory. To not have the need to enter all employees manually, of course local HR systems were connected and then as in many companies I think it was made use of that data to push into systems like Active Directory for example.
Of course there were in the beginning also many regional activities and local activities so we also had to harmonize into one global identity management system and bringing and connecting ITSM for access request and also the HR department then saw that it helps to have processes in one system and they also then moved into one global HR system which helped us also from identity management perspective.
So I'm putting here a few things to show you how we were moving into that direction and at that time we still had let's say a form and we still have it today where you need or the people need to enter the data for the B2B identities. So then over time of course from time to time our improvements like introducing access review were done or also improving life cycles like joiner and lever. During that time already Microsoft came up with Office 365 and this was definitely changing for us the situation quite a bit.
So from the very beginning we were not able to introduce this into the IGE solution so the infrastructure colleagues allowed let's say to use the functionality to invite guests into Teams and SharePoint. Because of that now we are facing the situation that accounts are showing up before we know about the identity record. Usually we prefer with this let's say traditional setup of externals to have first the identity clarified and then going to create accounts and doing this basic setup.
Of course then out of that we are now primarily dealing with two major setups that we have regarding the working profiles. One is let's say a full setup that brings the Entra ID account, mailbox and access to training system full-blown and the other thing is the guest account which is a bit more reduced one. But now we saw that to be able to moving forward and to be able to provide a solid B2B framework for our business we definitely need to integrate also and bring up identities for those externals that are working with guest accounts.
Simply to be able to ensure compliance and governance and to further support the collaboration area. In the past the workaround had the issue let's say that only minor information was collected from scripts and a few information were added by the hosts but it was not fulfilling our requirements to have a full-blown identity. Then because of that last year we started a project to integrate the guest accounts into our IGA framework and really to solve that gap to be able then also in future to move on to provision access also in our applications.
But by that also having it under control simply to govern them and as the guest accounts run a bit cheaper from Microsoft perspective of course that's also quite a reason to foster that. During that time in that project we definitely saw some challenges. You can imagine out of a long history quite a lot of stuff also comes with and this led to high customization and brings back end complexity and so on and this is really then a challenge to be able to bring in new people into the projects and being here fast to move on.
We still need to have always the internals acting simply to provide the identity information for the externals that's still a big challenge and then bringing a load to the whole organization. I already explained these different working sets that we have so we saw that our business is more or less thinking of account types here.
This was definitely a challenge to explain this that they can understand and as we brought up a high number of new identities that we didn't know about before in our process definitely some duplicates were identified and then all the supporting teams really had a lot of work to do to serve this and resolve this and identify them correctly and also there was a shorter timeline to make this all happen to register the identities so currently I can give you for example for the guest accounts the number per year it means that we are talking about 40,000 different guest accounts on our site and simply to extend them or to register them this is some high efforts so on the standard externals that we knew beforehand it was 32,000 so in total summary quite a high number.
If we look to the roles and responsibilities that we have around here you can see currently the internal can invite to collaborate for example with the guest accounts but also it's always needed to register new identities. Partner collaborators, the partner coordinator we have only included in that part to provide identity information and of course the B2B identity can completely focus on exchange and collaboration and simply delivering what's expected but they also for sure need to understand and follow our company rules and also for sure need to set up the device register for MFA that stuff.
The registration of new identities currently goes in one by one registration which can also then sometimes be a challenge especially for those internals that are responsible for a higher number of externals so I talked to some where it's more than 100. It was really a nice experience of course. Internals are also responsible to approve additional requests to extend from a lifecycle perspective.
Looking to the past and also especially during the project when we also did some recap we summarized here some lessons learned that I definitely want also to share and it showed is very important to understand the business cases and also the scenarios that we have. Here we see especially it was then important to explain how to change. Many externals start with a guest account but some point in time they need to full working setup. This is then important to be able to explain and we have business use cases along all our business units.
It starts from research and development where many externals are needed to support coming up with new research projects. Definitely then continuing on some substances and doing clinical trials. There is really a big amount of externals needed to make that happen that we can finally get the approval to go to market here and then this goes along towards let's say what we more or less know in our maybe also in our key environments as the classical use cases where externals are supporting in projects, consultancy or delivering managed services.
This is related that we see the very important to establish the user-centric process simply to ensure that end users can follow that. Sometimes it's a challenge if you have mainly technical people in the projects to change the few so in total technology is important but we also see really standards rock here to be able later on also to adopt and to be faster in development.
It's also important to involve the impacted user then into the testing that we really can ensure that it's also understood from them that they are using it the right way and also really to test all these scenarios to avoid surprises coming up at a later stage. The go live we did as I mentioned in a shorter time frame which is then more like a big bang. This was then for all a challenge also for the supporting teams and this is definitely something to think about to maybe to make it more nicer. In total let's aim for self-explanatory processes and establish by that a user-centric implementation.
This brings me how the future could look like. You can see here in the roles and responsibilities we have already or we think in future we want to move the registration to partners and coordinators but definitely also the B2B identity itself needs to be involved here much more.
With the guest accounts we are already directly in contact with them when we ask them to accept the consent and setting up MFA so should be easier to go with an identity registration and especially what we see here at EIC coming up all latest solutions we simply think that it is best if we can then integrate somehow with these identities that are issued by the governments. Why I'm thinking here on the governments there we think we can prove to our auditors that come from the authorities that this is the right trustworthy level.
If an auditor comes to us you know we all like it, we need to be polite and if we then can tell them we are using for that country this method what is also used for the government services I think this is really beneficial and doesn't bring up the question how did you prove, how did you verify that this is really working and also we don't want to simply only for the part of identity registration bringing up the burden for all B2B identities to register for an additional service it needs to be smooth and looks like in future everybody that goes for government services has a registration and we want to make use of that but we also expect that our vendors for ERM solutions and IGA solutions bring this functionality with and I really hope that we can participate from that.
Of course we see here the interns they still simply start and invite somebody for collaboration or initiated registration but this is then running smoother.
We also want to put functionality for to support the backloads here into the solution in future and in total definitely this needs to bring full transparency for the hosts and our partners but we can see still the power needs to reside on the internal on the host that it's clear what can these externals access and that we don't end up in something where it's again uncontrolled but as I mentioned we don't want to create a gap in future for audits still staying audit proof and this in total for future going into this direction we really hope that we can by that ensure that we are really bringing this together to the user-centric implementation but also keeping compliance and security in place really to keep the governance that we have and ensure that the right people have the right access at the time that they need it and yeah that's our few our story on that so I say thank you very much for your attention.
We have just one more minute left so if anyone has any questions. Thank you for the presentation we are really doing the very same thing at my company right now as we speak so the question is these guest accounts which establish do they sometimes get privileged access do they need to have kind of privileged access and how do you deal with that it's one question and another have you considered instead of giving the partners guest accounts to establish trust to their partner's own identity provider and use their original accounts instead.
Yeah okay currently from as we have not established that with guest accounts privileged access can go with this is I think still not confirmed from our security officers and I'm not sure if it will go that way so I can imagine that the strategy is not to go with each and everything if there is a tighter integration from the B2B identities like some in IT then need to access back-end systems I think then it still goes with a separate kind of access on that and the second one we have currently not established these direct trusts I think simply because we would have too many potential candidates to go for I think for some bigger companies we are partnering it could help yeah but it is not nothing we can take as a general approach.
Okay perfect thank you so much thank you thank you okay thank you.