
Groups are currently the most widely adopted method of managing application and resource security, however 70% of organizations do not
have a reliable group management solution. Gaining control over group membership is an essential first step in any enterprise
compliance initiative. EmpowerID Role Enforcer for Groups securely automates the entire lifecycle of managing groups: their initial
creation or discovery through self-service; their delegated administration; and their eventual retirement from use.
EmpowerID Role Enforcer for Groups automates and simplifies the complex process of provisioning, managing, and de-provisioning
groups in multi-directory environments throughout their entire lifecycle with detailed compliance tracking. Role Enforcer for
Groups inventories your enterprise directories and automatically discovers and monitors these protected resources for changes.
EmpowerID leverages its workflow and Role-Based Access Control (RBAC) framework to automate group permissions assignment and
membership management through RBAC policies and user initiated workflow requests.
EmpowerID's RBAC technology allows dynamic management of group membership by maintaining groups based upon roles and rules
derived from your directory data. When user information changes via request-driven workflows or from changes in external
directories, EmpowerID automatically updates the membership and native permissions of distribution lists and security groups.
EmpowerID's powerful Metadirectory provides rich reporting of group membership, and how users were added to groups, whether by:
RBAC policies related to job function and location; an approved workflow request; or a direct assignment of their user accounts
to groups outside of EmpowerID. EmpowerID makes a giant step forward in AD enterprise security by allowing the continuous
enforcement of Group membership and permissions based on RBAC policies. EmpowerID even gives business users the ability to
manage Group membership from within Microsoft Outlook.
The key issue in any strategy for centralizing the management of application and resource permissions using AD or LDAP
groups is the absence of any auditable linkage between the group and the application. As a result, AD and LDAP Groups can
quickly become a black hole for compliance initiatives. Organizations will often use complex group naming standards in an
attempt to "relate" groups to the resources they protect, but this is not secure or auditable. EmpowerID addresses this
need by extending the capabilities of AD and LDAP groups with Entitlement Management, which is external fine grain
authorization for applications and resources.
EmpowerID's RBAC Metadirectory is a complete Entitlement Management platform allowing protected Resources to be defined and
Groups to be used as relational roles conferring specific resource permissions and controlling application operations. EmpowerID
makes possible the attestation of any rights granted to any resource.
Key Features:
- Friendly web-based and rich Windows Presentation Foundation (WPF) user interfaces allow non-technical business users to participate in self-service and delegated administration of groups
- Flexible and friendly workflows automate new group requests with automatic rights-based approval routing and notifications
- Easy to use self-service workflows automate join and leave group requests with rights-based approval routing and notifications
- Role and location-based dynamic group membership policies automatically maintain membership based upon information in connected directories
- Time-based group membership automatically expires access
- Monitoring and inventory of directories detects changes, discovers new groups, and can roll back unauthorized changes
- Support for assigning native group permissions enables business users to manage group membership from within Microsoft Outlook
- Promotion of groups as relational RBAC roles allows 360 degree visibility over the resources they protect and the rights they grant
EmpowerID Role Enforcer for Groups provides organizations with centralized workflow and role-driven automation of the entire
group lifecycle management and enables groups to be a strategic part of any initiative focused on security, centralized
authorization, or compliance.
|