|
For networks that manage traffic for IT and IT Enabled Services
(ITES), ensuring that users have consistent access to the network
resources that they need while still maintaining a security policy
based on “least privilege access” can be challenging to deploy and
time-consuming to maintain, especially as the number of users
increases. To allow users access to resources on a per-project
basis, the Cloud Identity Engine now supports Dynamic Privilege
Access, a seamless, secure, and compartmentalized method to ensure
users can access only the resources necessary for their assigned
project.
When you enable Dynamic Privilege
Access for the Cloud Identity Engine, the user obtains access
through project-specific settings that isolate network resources
after selecting a profile and a project and successfully completing
authentication. This ensures that the user cannot gain lateral
access to other resources or attempt other access-based malicious
activity as well as helping companies to remain in compliance with
contracts and regulations.
Dynamic Privilege Access also helps users by increasing visibility
for what resources they can access. When a user logs in, all
assigned profiles and projects display, allowing the user to choose
which profile to use and which project to access. Users can have
multiple customer project assignments but access is restricted to
one project at a time.
Enabling Dynamic Privilege Access helps secure critical network
resources from unauthorized access while maintaining productivity by
ensuring that users are not prevented from accessing the resources
they need to complete their work.
|