Friday, June 5, 2015

5 Ways to Know You Need an IAM Solution

Implementing an identity and access management solution scares many organizations’ IT leaders and their CEOs for a variety of reasons. Though doing so does cost money, the expense of doing so is probably not as much as if saved because of resulting employee efficiencies among other savings factors. Cost and investment are only a small factor to be considered.
Every organization must address password and account management issues. They can be overlooked, of course, and assigned to be managed by IT departments as they arise, but usually in every organization, there is a certain point where the problems created by poor access and identity management procedures interferes with productivity in an overwhelming fashion and begins to cost the organization unneeded time and money. That’s when it becomes a major issue.
So how do you know when it gets to this point and when your organization needs an IAM solution? The following are five ways that you know an IAM solution is needed to improve processes.

1. An abundance of calls to the helpdesk
Whether it is password or access issues, when your helpdesk is receiving an overload of calls each day, the amount of time spent managing the process and time wasted by employees to re-gain access to their accounts can have a devastating effect on the productivity of the end user. Contacting the helpdesk, staring a new ticket and solving the account and password issue is time consuming and an extreme annoyance when an end user is in the middle of something; especially if they are with a customer at the time they are locked out.

2. Full-time employee for account management
Many organizations need to hire a full-time employee just to handle provisioning accounts and making account changes. If this is a full-time position at your company it is because you are handling the account management process manually, which is time consuming and prone to error, not to mention, it is very expensive to hire someone to do these manual tasks full time.

3. Employees don’t have all their accounts created on first day of employment
If you have employees who, on their first day of employment, cannot start working because of lack of access to the systems and applications they need, this is shows an inefficient process. It usually takes up to a week for a new employee to have all the correct access they need, which is a monumental loss of productivity, time and money.

4. Users are accidentally left active after they are no longer with the organization
Often, when employees leave an organization, disabling their accounts is overlooked and they are left active on the organization’s network. Though this is easy to overlook, it can create a security risk. Once an employee leaves, their access should automatically be disabled so they are no longer able to retrieve anything in the organization’s network.

5. Each system or application has different employee information
If each of your organization’s systems and applications has different employee information, this can be a difficult environment to manage, especially when trying to keep all data in sync. Each system needs to have the most current and correct employee information. When an employee gets married and changes their last name, for example, changing this information in each system can take a great deal of time and easily be overlooked.


Are any of these happening at your organization? If your organization deals with one or more of these issues, you may benefit from an IAM solution. So, even though implementing the solution can be scary, the process is actually a lot easier than dealing with issues that are already occurring on a basis, and can save your organization time in the long run.

For more information, please visit our website - www.tools4ever.com

Thursday, May 21, 2015

Access management for remote employees

Organizational IT leaders are most likely face a difficult decision related to allowing their employees to access company systems and information remotely or when working in a remote capacity. They are likely aware of the many benefits, but they have a dilemma: As more employees work outside of the office, how are they able to effectively provide efficient solutions to managing this data.
Solutions have adapted over the years so that employers can better benefit employees who work outside of the office. For example, technology solutions like single sign-on and self-service password reset, were first just for employees who worked in a collective work environment, in an office setting, but now they can now benefit all employees within an organization no matter the location of the employee.

For employees who work outside the company’s network, a single sign-on solution provides a way for employees to log into an “SSO anywhere” solution. This allows users who are not physically connected to the company network and want to use SSO, to log in from home or another location using their Active Directory credentials. In this scenario, users only have to enter a combination of password and user name once. This automatically logs them into all applications and resources across the company network and in the cloud, without the need of logging in again.
In regard to self-service password resets, many types of these solutions now allow users to log in and reset their passwords if needed, from anywhere. They simply choose the “Forgot My Password” button from the company’s log on window or portal and are then able to securely reset their passwords after answering several security questions. No need to burden the internal company helpdesk with calls seeking assistance.

For users on the go who use a laptop that does not have a connection to the company’s network, they click on the “Forgot My Password” button that is provided on the log-in screen. The SSO solution then presents the same questions as the normal self-service password reset procedure (with network connection). After correctly answering the questions, users can then be automatically logged onto the machine. In addition, many self-service reset password solutions also are mobile-friendly for those using their mobile phone, tablet or other device.


So, while remote employees might not enjoy other benefits of working at the office — such as free coffee, in-person camaraderie and copies — they can still benefit from using the company’s solutions.

For more information, please visit our website: www.tools4ever.com .

Friday, May 15, 2015

Wild Ways People Remember Their Passwords, and Why Breaches Are Likely Because of Them

Everyone has done it, used some kind of wild way to remember user names and passwords. Let’s face it, the rules for managing passwords is overwhelming. People are required to remember numerous sets of credentials for all of the systems and applications they need to access their job and personal life, but it’s often too difficult to remember them all.

In addition, passwords often are required to be complex with several different symbols and characters, and they often need to be changed every month or so. Given all of the rules and parameters, how is anyone supposed to keep track, and remember, all of this information on top of all the work they need to complete, PIN codes they need to recall and every other detail that takes up much needed bandwidth?

How do most people remember their passwords? Chances are they keep all of their pass codes in some type of non-secure method to remember them. Given my line of work with clients facing complex password issues, I’ve witnessed many wild ways in which end users use to remember passwords. Frighteningly so, some people even believe that their methods for password “storage” are safe and don’t realize that they are actually putting their organizations at risk.
Though organizational leaders may think that requiring employees to use complex passwords that get changed often is making their network secure, reality is this is often counterintuitive and leads employees to user unsecure methods.

Here are just some of wildest ways I’ve seen people store their passwords:
  1. Since employees feel they have to constantly login, many folks keep their credentials in front of them, written on Post-It notes, pasted to their computer screen in plain sight of passersby. That just makes it a lot easier for hackers to gain access to critical information.
  2. Some people think that if they hide their passwords, this will keep their information more secure. Many employees, however, actually keep their password sheets in their desk drawer or under their keyboards, falsely assuming no one will just open the drawer or move the keyboard and take a peek.
  3. Recently, one of our employees visited the doctor’s office and saw that the receptionist actually had her passwords listed on a recipe card atop the desk next to her monitor in clear view of everyone coming and going. Next to that card were instructions – step by step -- for accessing all of her accounts.
  4. Some people even use an invention that they believe is helping them keep their passwords safe: A type of notebook that looks like a phone book allowing them to write down their passwords and organize them. Sure, this is good for organization, but what happens when someone finds the notebook and has access to all of the credentials?
Chances are, many employees in virtually every organization use these methods, but these strategies can cause security risks for any organization. Luckily, though, there are easy ways to stop employees from using such non-secure methods.

One way is with a simple single sign-on solution. An SSO allows employees to create a single set of credentials for all of their systems and applications, eliminating the need to write down passwords or use other non-secure methods for storing their information. Employees simply log in with their credentials and thereafter are authenticated in each of their applications automatically after they are launched.


So, while it may be funny to read how employees remember their passwords, it won’t be funny when your organization faces a security breach because of it.

For more information, please visit our website at www.tools4ever.com

Friday, March 27, 2015

How To Implement and Manage a BYOD Policy (and Keep IT Happy)

Implementing a “bring your own device” (BYOD) policy for your organization can be extremely beneficial, but if not done correctly can also cause several problems. One of the main reasons that companies implement BYOD is to lower their costs associated with purchasing a large number of computers or tablets.

Many security issues can arise, as well as an increase in time spent by the IT department on setting up and monitoring all of the employee’s devices. Though BYOD may lower costs of technology, if not implemented correctly it can actually result in higher costs in areas such as the time and support from the IT department.

It’s important to correctly set up and manage your BYOD implementation right from the beginning.

Here are several ways your organization can get the most out of a BYOD policy while easily managing the risks:

Set Up a BYOD Policy From the Beginning:

Set Up Guidelines and Rules

By drawing up a set of rules right from the beginning, your employees will know exactly what’s expected from them, leaving little room for confusion. These rules will also allow the organization to define any repercussions if employees misuse or take advantage of the use of the BYOD policy.

Set Guidelines for the Types of Devices Allowed

One of the top issues with BYOD policies is that there are many different types, brands, operating systems, and more for devices.

When employees register their device with the company, they then expect the IT department to support it and resolve any issues with the device, which can be a headache for any IT department.

An organization needs to set, right from the beginning, which types and brands of devices they are going to support.

Implement a Mobile IAM Solution in Conjunction with BYOD

Easily Set Up and Manage Devices

In addition to all employee accounts, admins will now also have to set up and register all employee devices. In the beginning especially, there is a large influx of new devices that need to be added, which is extremely time consuming if it is done manually.

Mobile IAM solutions allow admins to easily add new devices by simply adding them in Active Directory. If desired, they can also allow users to register their devices themselves. End users simply fill out a web form that is set up for a work flow request, which will then be automatically be sent to the appropriate manager or department for approval.

Once the company decides which devices they are going to support, this can be set up in their mobile IAM solution. When a user then tries to register a device, only those that the company supports will be able to be registered.

Securing the Company’s Infrastructure

Since employees will keep their device once they leave the organization (because they own it!), there is the potential for them to have continued access company data.

Companies need to ensure that when an employee leaves they no longer have access to the company’s network and data. Though the solution seems simple–disable the user from the system and applications they have access to–this often, more times than not, goes unnoticed and the user remains active.

This is because IT needs to be notified of the employees leave and then manually disable them from all systems and applications individually. If an IAM solution is implemented, once an employee leaves the organization a manager can automatically disable the user’s access and deactivate their access to the network, ensuring the security of the company’s data.

By following these guideline organizations can hopefully gain the most out of BYOD while mitigating the risks that can potentially occur.


For more information, please visit our website - www.tools4ever.com

Friday, March 20, 2015

Reducing Organizational Costs by Eliminating Costly Mistakes


One of the major topics constantly on the minds of organizational leaders is, “How can I reduce costs?” Many times this is in terms of direct costs, such as employees and materials, as managers tend to look at employees’ salaries, materials, etc., used in day-to-day activities.

Frequently overlooked is the amount of time and money that goes into other aspects of running the business that cannot be physically seen. These include such things as the management of accounts, passwords, applications and other solutions. While not at first noticeable, these costs can add up, and there are ways in which expenditures can easily be reduced. If management and leaders sit down and actually add up how much it is costing them to manage employee accounts and passwords, the cost can be astonishing. Not only is the waste physical dollars, but can also be hours spent on processes that can be made more efficient.

The following are just a few of the common ways that an organization may be wasting money, as well as the actions that can be taken to easily reduce these cost wastes.

Account and Access Management Costs


Account and access management is a task that may be costing an organization more money than previously thought. In many cases, multiple staff members focus solely on provisioning, making changes and de-provisioning accounts throughout the year. Often, this is because these tasks are performed manually for each employee’s account, and while it is not difficult, they are extremely time-consuming tasks.

Frequently if there are a large number of employees beginning employment at a company, provisioning accounts in all the correct systems and applications for each employees can take hours. Then there is the issue of temporary or contract employees. Organizations who have employees who are only there for a short amount of time, and have frequent movement, spend much time provisioning, changing and de-provisioning these accounts. They need to ensure that these temporary employees have the access they need to perform their jobs while they are there, but then also that they are promptly disabled once they are no longer working for the company.

If there are full-time employees handling these account management actions, chances are they are highly experienced and trained and high-earning IT employees handing these task. Essentially, organizations are paying technical employees to perform these simple tasks.

In addition to the expenses of manual account management, access management may be costing organizations more money than is necessary. Between the provisioning, de-provisioning and movement of accounts, one item that tends to get overlooked is exactly who has access to what, who actually needs access to certain systems and applications and how many accounts are left active that need not to be. So, for example, companies may be paying for more license costs for an expensive application than are actually needed. Or even worse, they may be paying for accounts for people who no longer even work for the organization. These are all costs that might look minimal but when added up, are costing companies a substantial amount of money.




Password Management

Another major source of money waste is with the management of passwords. META Group research, conducted on behalf of PricewaterhouseCoopers, concluded that helpdesk tickets for password resets cost annually $60.93 per employee and 45 percent of all helpdesk calls are for password resets.

This doesn’t take into account the cost of time of employees who have to deal with password resets. Think about the time it takes for both the end user and the IT employee to reset a password.  Everyone is familiar with how annoying it is when they forget their password. You need to stop what you are doing to call the helpdesk, who in turn create a helpdesk ticket and manually reset your password. In addition to the annoyance, it has a negative impact on customer service if this happens to an employee when they are assisting one of your customers.

Though it is not a highly technical task, it takes time away from the both the end user and help desk employee, time which could be used doing something more productive.

Cost Saving Solutions

So how can these costs be reduced without a huge implementation of an expensive solution? First, let’s take a look at the account management issues. Something as simple as a solution that automates the account management process can save a great deal of money. By automating the account management process, highly technical staff no longer has to handle tasks that can easily be performed by other employees. The task can be easily delegated to a less technical helpdesk staff member or other employees in the company. With an automated account management solution, less technical employees can easily manage employee accounts using a secure form. They simply enter or make changes to an employee account in Active Directory, and the changes are automatically made in the connected systems and applications. Instead of having to manually create, change or disable accounts, the employee in charge of account management can just enter the information into the pre-set form so it is easier, and errors become less likely.

This is also beneficial when it comes to license costs. Instead of paying for accounts for employees that are no longer with the company, an automated account management solution allows you to simply check a box in the employee’s profile and all accounts are automatically disabled. Many solutions also provide an overview of access rights. This allows managers to see exactly who has access to what systems and applications to ensure they are paying for the correct number of licenses. If, say, there are any errors in access rights, an automated account management solution allows them to easily be corrected.

So what about the password resets? The easy solution to this is a self-service password reset solution.  Just like on many banking websites, numerous organizations have been implementing password reset solutions for their employees to use in the work setting. Employees simply enroll by providing answers to several challenge questions and when they need to reset a password the user simply provides the correct answer to the questions and are able to easily and securely reset their passwords without having to contact the IT department. This one small solution can save an organization hundreds or thousands of dollars each year, as well as alleviate many headaches for organizational leaders.

These simple solutions are both cost efficient and allow organizations to easily reduce costs for otherwise costly processes that often take up a large amount of time.

For more information, please visit our website; www.tools4ever.com

Friday, February 20, 2015

Identity and Access Management: Hot or Not?

Identity and access management (IAM) is increasingly being deployed within organizations across multiple sectors as they recognize that a progressive approach to IAM is crucial for their companies. Though not yet mature, the IAM market continues to grow because of a number of influences and developments. Some of the developments include, among others, cloud computing, web solutions, information governance and BYOD.

To better understand how the market in moving toward IAM, let’s take a look at some of the developments and their impacts.

Moving to and using the cloud

On-premise solutions are being used less and less. Where hardware and applications were previously used in abundance and managed internally, solutions are now being moved to the cloud with an increasing amount of frequency. A main advantage of moving to the cloud is that this strategy allows organizations to make the work of their employees more flexible and allows them to work wherever they are located and to be far less dependent on local servers and other hardware. Therefore, as long as an Internet connection is available, staff can gain access to their applications and to their work.

Also, cloud applications impose far fewer demands on the equipment on which the work is done. What this means specifically is that these solutions grant employees more opportunity to work more freely from any device, be it a laptop, tablet or smartphone, as well as a desktop computer.

However, the cloud has little benefit for making the management of identity and access management solutions easier, unfortunately. Where tight integration arrangements within a network were the norm, the required collaboration with multiple cloud suppliers -- which all have their own standards -- means processes can becomes more difficult to manage in some cases. Stated another way, cloud applications have their own password policies, which means traditional LDAP authentication with the Active Directory becomes considerably more complex in it set up. Automatic management of user accounts and rights within the application also is increasingly more difficult. Finally, in addition, existing on-premises APIs no longer work over the Internet, which requires the functional application manager to operate with a manual user management interface.

WebSSO (single sign-on)


 With the growing use of cloud solutions, employees continue to have difficulty keeping track of their account credentials; this is not a new problem, but one that seems to have exacerbated recently. An often attempted solution to this problem is to offer staff and employees a portal where direct links to the various URLs for the web applications are clustered. Employees then only need to remember one URL, which is that of their own portal. The problem is, though, employees still need to remember a number of usernames and passwords once they’ve access this one URL because the applications hosted within it still need to be accessed.

A simple fix to this problem is one many are beginning to realize -- organizations can deploy WebSSO. With single sign-on (SSO), end-users only have to authenticate themselves once, entering a username and password from the Active Directory. WebSSO then takes over the log in processes, allowing users to not have to enter log in details again when wanting to open an additional application. With this approach, a user only needs to be authenticated once when entering the portal and the single sign-on software takes over the login processes for the cloud applications. This process is not only more user friendly, but also is more secure as it reduces the need for end users to write down credentials down or store them improperly to remember them.

Identity and access governance


Strict regulation in a variety of industries and across multiple sectors is helping make the use of IAM solutions more prevalent. Organizations must comply with audits or information requests, so many leaders require that their organizations clean up their information stores and in so doing, they put any rights pollution under the microscope. Since rights are often issued on the basis of copy-user or template users, pollution can easily creep in during the initial granting of rights. Manually charting the rights granted is highly complicated and time-consuming. In many instances continually managing the rights structure is simply not feasible.

Therefore, by using identity and access governance, organizations are able to easily ensure that employees only have the access to the network resources required to perform their duties. In the past, identity and access governance was largely the domain of financial institutions and major international concerns. Because of regulation and the increased need for the protection of data, governance of information is becoming more prevalent to a variety of institutions, including those in healthcare, small to enterprise companies and other commercial operations.

Broad access to information systems

Another recent development affecting the expansion of IAM solutions throughout enterprise is the increasing need to make information widely available to many parties. Growing numbers of people want or need access to information and information systems. For example, local authorities and  municipalities now allow the public regular access to their information systems to access certain data points or records. Within healthcare sector, patients require the ability to view their own medical details through secure portals and web-based sites.

Organizations are taking the initial steps and alongside their Active Directory are building up an LDAP store to enable broader access to information systems. This means that in addition to staff, external parties must also be provisioned and made known within the network. A user ID is needed and people must authenticate themselves to gain access to the information systems. With identity and access management it is possible to automate the provisioning and authentication process to reduce the overwhelming amount of manual tasks the IT department needs to perform.

Overall, the IAM market is hot continues to grow, evolving to meet the needs of organizations and the changes that they are making within their companies to operate more efficiently and change with the changing times.


For more information, please visit our website at www.tools4ever.com.

Friday, February 13, 2015

Reducing Menial IT Tasks through Automation and Provisioning

There are many identity and access management solutions out on the market that claim to have all sorts of magical benefits for the organizations they serve. If your firm is not having any major IAM issues, though, you may be wondering, “Does my organization really need any of these solutions?”

The truth is that you may believe that your systems are secure, that you have given your employees all the tools to be efficient and that accounts are being provisioned effectively for your employees. But, if you take a closer look at these processes, you may see that there is much room for improvement. 

Although there might not be a major issue that needs to be solved, an IAM solution can save your organization significant time and money and easily help meet audit requirements. The following are just a few of the processes that can be drastically improved by an IAM solution.

Efficiently provisioning accounts

Accounts seem to be getting provisioned by your system admins in a timely manner, so why would you need any type of solution in place? If you begin to add up the time spent on this task, though, especially for large organizations, the process of provisioning accounts can be daunting and result in many errors.

Often, new employees do not even have their network accounts correctly provisioned their first day of employment and have to wait several days to have their appropriate access set up. These are wasted dollars for your organization, as the employees wait unproductively. In addition, provisioning accounts is a menial task that takes up a considerable amount of time of advanced IT employees or even requires the organization to have a full-time employee just to perform this task.

A case example of this was Lifestyle Hearing. The organization spent a great deal of time ensuring that employees had accounts properly created. Franco Butera, IT director, said, “This task took about half an hour for IT to complete, and that was only if we had all the correct information from the beginning. If not, we had to track down the employees in an attempt to get the information, and wait for a response that could take up to an hour or more.”

The organization implemented an automated account management solution that allows human resources to have controlled access through a Web-based form. They can now easily create accounts by entering the employee’s information, defining their profiles and which systems they need to access. Lifestyle Hearing previously had a four- to five-day window for account creation, but using an account management solution, employees are now able to have their accounts created right away and start working the same day they are hired.

Easily securing the network

Your organization may have taken many precautions, and you believe that your network is safe as it can be. However, take a walk past your employees’ desks and see the Post-its they have scattered around with their credentials written on them, or do a little searching and find a paper with a list of their credentials in their desk drawer, often with detailed login instructions. This is not only an annoyance for your employees, but also a major security risk.

This was the issue that Needham Bank was having. End users at the bank needed access to several different systems and applications to properly assist customers. “End users became frustrated at the number of disparate passwords they had, and the frequency they would have to enter the user names and passwords,” said James Gordon, first vice president of information technology at Needham Bank. The organization implemented a single sign-on solution that allows employees to log in with a single user name and password, and thereafter gain access to all systems and applications for which they have authorization, drastically reducing the login time.

With a single set of credentials, employees no longer have to write down their passwords to remember them, which resulted in greatly improved security.

Greater productivity — efficiently reset passwords

You may not think much about when your employees need their password reset, but this is actually the single most common call that employees make to the help desk. Though this is an easy task to manage, it is time consuming for both the help desk and the end user. In addition, this is a major problem for employees who work outside the times of the help desk. If end users work nights, weekends or even in a different time zone and are locked out of their account and unable to contact the help desk to reset their password, this leaves them unable to access their applications or system until the help desk receives and processes the request, leaving them unproductive.

National Geographic experienced this issue. Nat Geo’s employees need to access several cloud applications, including Google Apps, with different credentials for each to perform their jobs. This became an issue when employees had difficulty logging in because they forgot their passwords and were unable to contact the help desk as they are located in different time zones around the world, outside of the business hours of the help desk.

With a self-service reset password solution employees simply answer predefined security questions and are able to reset their passwords, even in the middle of the night, without contacting the help desk. This allows them to quickly resolve their password issues and continue with their work.

Overall, though your company might not be having a major IAM issue that needs quick attention, there are many IAM solutions that can greatly improve upon the processes that your organization has in place. No matter how big or small, or what industry your company is in, it is beneficial to at least take a look at how an IAM solution can help improve your organization. 


For more information, please visit our website at www.tools4ever.com