Directory-as-a-Service Primer (DaaS)



Similar documents
JumpCloud is your Directory-as-a-Service. A fully managed directory to rule your infrastructure whether on-premise or in the cloud.

Easily Managing User Accounts on Your Cloud Servers. How modern IT and ops teams leverage their existing LDAP/Active Directory for their IaaS

owncloud Architecture Overview

An Overview of Samsung KNOX Active Directory and Group Policy Features

Integrating Single Sign-on Across the Cloud By David Strom

NCSU SSO. Case Study

identity management in Linux and UNIX environments

Microsoft Enterprise Mobility and Client Futures

owncloud Architecture Overview

Pronto Connect Preparing for a more connected future. White Paper

activecho Frequently Asked Questions

8 REASONS MORE COMPANIES ARE MOVING THEIR BUSINESS PHONES TO THE CLOUD

Directory Integration with Okta. An Architectural Overview. Okta White paper. Okta Inc. 301 Brannan Street, Suite 300 San Francisco CA, 94107

Top Eight Identity & Access Management Challenges with SaaS Applications. Okta White Paper

An Overview of Samsung KNOX Active Directory-based Single Sign-On

How to Provide Secure Single Sign-On and Identity-Based Access Control for Cloud Applications

Move your business into the Cloud with one single, easy step.

Centrify Server Suite Management Tools

Top 8 Identity and Access Management Challenges with Your SaaS Applications. Okta White paper

Direct Control for Mobile & Supporting Mac OS X in Windows Environments

managing SSO with shared credentials

E-Guide SIX ENTERPRISE CLOUD STORAGE AND FILE-SHARING SERVICES TO CONSIDER

Directory Integration with Okta. An Architectural Overview. Okta Inc. 301 Brannan Street San Francisco, CA

Secure any data, anywhere. The Vera security architecture

Three Ways to Integrate Active Directory with Your SaaS Applications OKTA WHITE PAPER. Okta Inc. 301 Brannan Street, Suite 300 San Francisco CA, 94107

Kaseya IT Automation Framework

White Paper. Anywhere, Any Device File Access with IT in Control. Enterprise File Serving 2.0

Enterprise Mobility Suite (EMS) Sean Lewis Principal Partner Technology Strategist

The PortalGuard All-In-One Authentication Solution-set: A Comparison Guide of Two-Factor Capabilities vs. the Competition

Overview of Microsoft Enterprise Mobility Suite (EMS) Cloud University

Avoid the Hidden Costs of AD FS with Okta

Building a Cloud-Ready, Future-Proof Identity Infrastructure:

Google Identity Services for work

Identity. Provide. ...to Office 365 & Beyond

What s New in Centrify Privilege Service Centrify Identity Platform 15.4

FileDrawer An Enterprise File Sharing and Synchronization (EFSS) solution.

White. Paper. Enterprises Need Hybrid SSO Solutions to Bridge Internal IT and SaaS. January 2013

WHITEPAPER. 13 Questions You Must Ask When Integrating Office 365 With Active Directory

Office365 Adoption eguide. Identity and Mobility Challenges. Okta Inc. 301 Brannan Street San Francisco, CA

Grow Your Business with Confidence

Top. Reasons Federal Government Agencies Select kiteworks by Accellion

Connecting Users with Identity as a Service

White Paper. What is an Identity Provider, and Why Should My Organization Become One?

How To Deploy Cisco Jabber For Windows On A Server Or A Network (For A Non-Profit) For A Corporate Network (A.Net) For Free (For Non Profit) For An Enterprise) Or

Red Hat Enterprise IPA Identity & Access Management for Linux and Unix Environments. Dragos Manac

Better Together with Microsoft Windows 10 and Azure. Ken Wong APAC Product Marketing Director Citrix

Identity and Access Management Integration with PowerBroker. Providing Complete Visibility and Auditing of Identities

EXTENDING SINGLE SIGN-ON TO AMAZON WEB SERVICES

DATA BREACH RISK INTELLIGENCE FOR HIGHER ED. Financial prioritization of data breach risk in the language of the C-suite

How cloud computing can transform your business landscape

IT Peace of Mind. Powered by: Secure Backup and Collaboration for Enterprises

The Centrify Vision: Unified Access Management

CA Federation Manager

STRONGER AUTHENTICATION for CA SiteMinder

Identity & Access Management in the Cloud: Fewer passwords, more productivity

G Cloud 6 CDG Service Definition for Forgerock Software Services

WHITEPAPER. NAPPS: A Game-Changer for Mobile Single Sign-On (SSO)

Federated single sign-on (SSO) and identity management. Secure mobile access. Social identity integration. Automated user provisioning.

A Forrester Consulting Thought Leadership Paper Commissioned By Brother. December 2014

How cloud computing can transform your business landscape.

The Top 3 Identity Management Considerations When Implementing Google Apps for the Enterprise

People-centric IT: Bedeutung für das Identity und Access Management. Uwe Lüthy Solution Sales Specialist Core Infrastructure Microsoft Schweiz Gmbh

Leveraging SAML for Federated Single Sign-on:

Hybrid Cloud Identity and Access Management Challenges

MY1LOGIN SOLUTION BRIEF: PROVISIONING. Automated Provisioning of Users Access to Apps

whitepaper Absolute Manage: Client Management Managing Macs in a Windows Environment

Extend and Enhance AD FS

Moving Single Sign-on (SSO) Beyond Convenience

Device Lifecycle Management

THE MOBlLE APP. REVOLUTlON. 8 STEPS TO BUlLDING MOBlLE APPS FAST ln THE CLOUD

Agenda. Enterprise challenges. Hybrid identity. Mobile device management. Data protection. Offering details

Directory service for centralised access to distributed contact data

ORACLE BEEHIVE ENTERPRISE MESSAGING SERVER

Protecting Data with a Unified Platform

Mobile device and application management. Speaker Name Date

Symantec Mobile Management Suite

Accenture Cloud Platform Unlocks Agility and Control

WHITE PAPER. Active Directory and the Cloud

Where are Organizations Today? The Cloud. The Current and Future State of IT When, Where, and How To Leverage the Cloud. The Cloud and the Players

How To Manage A Plethora Of Identities In A Cloud System (Saas)

USING FEDERATED AUTHENTICATION WITH M-FILES

How To Secure Shareware Kiteworks By Accellion

Real-World Scale for Mobile IT: Nine Core Performance Requirements

How Desktop-as-a-Service Can Solve Higher Education s End-User Computing Challenges

Six Best Practices for Cloud-Based IAM

CTERA Cloud Storage Platform Architecture

Speeding Office 365 Implementation Using Identity-as-a-Service

Apps. Devices. Users. Data. Deploying and managing applications across platforms is difficult.

Storage Made Easy. Cloud File Server Overview

SERENA SOFTWARE Serena Service Manager Security

MaaSter Microsoft Ecosystem Management with MaaS360. Chuck Brown Jimmy Tsang

Quest One Identity Solution. Simplifying Identity and Access Management

Transcription:

Directory-as-a-Service Primer (DaaS) Directory-as-a-Service or DaaS is the modern adaptation of traditional Microsoft Active Directory (AD) and Lightweight Directory Access Protocol (LDAP). It is a cloud-based service optimized to authenticate, authorize and manage user access to IT resources across any device type, on any operating system, with any IT or Web-based applications located on-premise or in the cloud. As a simplified, yet more powerful and economical approach to a user directory, DaaS changes the game for IT admins. Organizations are struggling with the costs and management overhead of maintaining on-premise AD or LDAP in the face of increased IT complexity. These legacy solutions are losing out to new cloud-based alternatives that are streamlined, secure, and easy-to-use. DaaS solutions support all major OS platforms and are designed to control and manage user access to both internal and external IT resources such as servers and applications. In short, a cloud-based directory makes it easier for admins to connect their employees to the IT resources they need, wherever it exists. Why DaaS? DaaS is the secure connection and management of employees and IT resources through a single, unified cloud-based user directory. It is the single point of authority and authentication for a business s many employees and access rules. Additionally, it s a central source of truth regarding employees and system users for other complementary solutions such as single sign-on (SSO) technologies. 1

The Benefits of DaaS IT admins are underwater with a crushing load of tasks. Meanwhile, cloud-based solutions have become a new staple for IT admins. Cloud-based software off-loads the setup and on-going operations of core IT services to experts. For example, a common cloud-based business solution is Gmail, having supplanted many legacy email systems installed and managed historically on-premises. A SaaS-based directory is an analog to this. By using a cloud-based approach for a user directory, IT admins outsource the setup, configuration, and on-going maintenance of their central user directory. In return, they reclaim precious time, increase security, and gain valuable control and visibility over their IT environment. 2

How DaaS Works DaaS is a critical IT service for authenticating, authorizing, and managing users, devices, and applications. A brief description of each function is described below. Authentication JumpCloud can act as your directory of record or an extension of your existing directory. Requests to authenticate users are sent to JumpCloud via LDAP protocol or our REST API. The JumpCloud agent can also be deployed on your Windows, Mac, and Linux devices for task and policy management, survivability and security auditing. Authorization JumpCloud is your authorization solution, ensuring that the right users have the right access to your IT resources. JumpCloud can manage group membership and sudo access. It can also execute a command when users are added to or removed from any device. Management A critical part of a DaaS solution is the ability to manage Windows, Mac, and Linux devices at scale. DaaS simplifies task execution on devices including globally updating policy settings, modifying registry settings, applying patches, and changing system configurations. It ensures consistency across your environment, by allowing you to group like objects and apply the same policies and configurations across them. 3

Why DaaS is Needed Now For companies that are leveraging the cloud, have Macs, are on Gmail, or all of the above, a modern solution to the directory is desperately needed to centrally manage and control user access. As most IT admins know, it s hard to patch directory solutions together to accommodate the changing IT landscape. Specifically, while moving to the cloud solves many problems, it also creates others. For example, cloud servers hosted at AWS or Digital Ocean are currently out-of-purview for most on-premise hosted directory solutions. As a result, end user cloud apps such as Salesforce and Dropbox are managed by single sign-on vendors which require integration back to the core user store. Macs are the fastest growing end-user compute device, and they re causing tremendous problems and pain for IT administrators. For most organizations, Macs are not managed devices. That means IT has little control over access and even less over the device s security posture. As more device types appear including phones and tablets, the IT organization is blind to them. These devices will invariably have core digital assets, but will not be managed. That s a recipe for disaster and one that needs to be solved quickly. The move to Google s enterprise email and productivity services, Google Apps and Gmail, is bifurcating the once dominant Active Directory/Exchange tandem. The challenge is that as organizations move email to Google, they are still stuck with an on-premise directory an anchor preventing their full move to cloud services. Google s user store is not meant to be a complete directory with full authentication, authorization, and management services. It was largely meant as a contacts list and control point for Google services. 4

Additionally, single sign-on solutions are very popular today with investors, but unfortunately do not solve core internal IT problems. IT admins know that even with SSO solutions for their Web apps, they still need to manage their desktops, servers, and internal Web apps, not to mention their cloud servers. And, the way that they do that today is through a core user directory and management tools. These challenges are driving the innovation of DaaS. With decades of history and little innovation, solutions such as AD and LDAP have set a foundation for what will be needed in the cloud era, but unfortunately they have not made the jump. This next generation directory will stand on the shoulders of these giants, but will carve a new path for smart, modern organizations. Who Should Use DaaS? Modern organizations that already leverage the cloud are ideal candidates for DaaS. IT admins at these companies know first-hand the challenges of managing access to cloud servers and infrastructure. Further, many of these companies are leveraging Google Apps and Macs, so they know all too well the pain of user and device management. The cloud era is an opportunity, but also a significant risk for organizations. A modern directory delivered as a SaaS-based service capitalizes on the opportunity while decreasing risk for organizations. About JumpCloud JumpCloud, the first Directory-as-a-Service (DaaS), is Active Directory and LDAP reimagined. JumpCloud securely connects and manages employees, their devices and IT applications. Try JumpCloud s cloud-based directory free at jumpcloud.com. 5