Thursday, November 12, 2009

Provisioning Cloud Services like Google Apps

“You must not blame me if I do talk to the clouds.”

Henry David Thoreau


While SaaS/Cloud/SOA services … pick your buzz word, are great alternatives for small to medium size organizations (SMB), using them requires Provisioning & Federated Security which are challenges even for large Info Sec departments in Fortune 100 organizations.


In particular Google Apps™ provide small businesses, universities, schools, and other organizations the option to outsource collaboration tools, etc. for low- or no-cost. But the issue of managing user access to those applications is still the responsibility of the organization.


So what is the solution?

  • The Aegis Provisioning Appliance for Google Apps delivers the tools needed to automatically add, modify, and delete accounts by expanding organizations existing directory services and provisioning infrastructure.

  • The appliance provides a full set of account management tools through real-time secure interfaces to Google Apps.


How does it work?

  • Automates the creation, update, deleting of accounts based on actions in an organizations existing directory service (e.g. Microsoft Active Directory or LDAP)

  • Provides delegated administration for defined users to add, update, delete accounts

  • Creates predefines web-based workflows including approval chains

  • Supports future expiration dates or renewal approvals

  • Simplifies the use of contractor or guest accounts with access registration/sponsorship forms


What is the compliance impact?

  • The Aegis Appliance ensures that account creation, updates, deletes are done in line with the organization’s policy.

  • Rules can be easily applied (and demonstrated) so a contractor needing access to Gmail for one week and then automatically disabled.

  • Allows organizations to start with Google Apps and scale into a full enterprise IAM deployment from Oracle


So how do I deal with the security issues?

  • The Aegis Provisioning Appliance can be combined with the either Aegis Password Management Appliance or the Aegis SSO Appliance

  • This provides users with a seamless login experience to their new Google accounts through either synchronization of passwords to Google, or web-based SSO.


Why are appliances beneficial to SMB's?

  • AegisUSA Appliances are a revolutionary approach to IAM, providing enterprise-level functionality in an appliance form factor

  • The 80/20 rule - This reduces cost through simplicity, removing the complexity by focusing on the most common use cases

  • Higher time-to-value for an identity solution through lower implementation costs

  • Provides a fully configured HW/SW environment, leveraging enterprise-class components


This is part of a broader evolution of IAM as SMB's are becoming a growing consumer of IAM technology which is the driver behind the AegisUSA strategy.







After all there are only more Cloud based services to come. As Judy Garland put it "Behind every cloud is another cloud.”


To learn more visit Aegis USA


No comments:

Post a Comment