Quick viewing(Text Mode)

Universidad De La Rioja Manages AD More Efficiently

Universidad De La Rioja Manages AD More Efficiently

CASE STUDY 7,600 students, 700 employees 700 7,600 students, www.unirioja.es Website Employees Country Industry Company Key Facts Education Universidad de La Rioja La de Universidad Products Results Challenges error-prone, and a lack of detailed detailed risks. auditing security of introduced lack a and error-prone, and time-consuming was accounts of Moreover,owners. provisioning resource and staff desk tasks help to these of delegation granular secure, not could tools Native of administration Active Directory. routine on time much too spending were Rioja La de Universidad at administrators Systems Active Roles • • • auditing detailed and access based role- with security Enhanced interface web easy-to-use an by delivering operators desk help of productivity Increased tasks administrative routine of delegation granular secure, enabling by time IT valuable Saved

1993 andtoday istheonlyhighereducationandscientificresearchcenter The Universidad deLaRiojawas foundedintheacademicyear 1992- IT staffattheUniversidad deLaRioja were tryingtomanageActive Staff foundthetoolstobetoocomplexandnotsufficiently flexibleor Directory (AD)usingnative tools,butfoundthosetoolstobeinsufficient. professors andresearchers,250staffmembers. to createformswithspecific values tofacilitatebasicadministrative tasks, or toprovide closedforms forstandardprocesses. intuitive. Inparticular, theywere unabletoprovision accountsefficiently, in theRiojaregionofSpain.Theinstitutionhas7,600 students,450 staff withActive Roles fromOneIdentity routine taskscanbesecurelydelegatedtohelpdesk Systems administrators deliver morevalue nowthat ADmanages more efficiently Universidad Rioja deLa Managing Active Directory is difficult with native tools native with difficult is Directory Active Managing “Thanks to Active Roles, systems administrators no longer have to perform routine administrative tasks without any technical value.” Jesús Mª Álvarez Ruiz, Systems Engineer, Universidad de la Rioja

Active Roles simplifies In addition, the university comprehensive AD technical knowledge. The quality was finding that systems management of the product and functionalities administrators were spending in terms of deployment time too much time on routine The Universidad de la and ease of use are clear administrative tasks. It wanted Rioja began looking for a differentiating factors over to be able to delegate those comprehensive AD management other solutions in the market,” tasks to support engineers, help tool. IT staff were already using notes Álvarez. desk operators and advanced several One Identity tools, users—but without giving them including Quest Toad for Oracle. Give control over resource broad administrative rights, and It therefore decided to evaluate access to the resource while being able to audit their One Identity’s AD management owners, not IT individual actions. The university solution, Active Roles, as well also wanted to offer self-service as Microsoft Forefront Identity Using Active Roles, the capabilities to users—and, of Manager (FIM). university has been able course, it wanted all of this to delegate appropriate functionality through an easy-to- After carefully reviewing both administrative authority to use web interface. products, the university selected help desk operators and the One Identity solution. heads of service throughout “Native AD management was Active Roles enables easy the organization, enabling not as comprehensive as administration of user and group those staff members to act we wanted. We sought to accounts, strictly enforced role- as delegated administrators administer identities, improve based security, day-to-day of the resources assigned to administration monitoring, identity administration, and their services. And because the allow end-user self service, built-in auditing and reporting. solution’s web-based interface and enhance security in a The Universidad de la Rioja was is easy to use, the delegated centralized way, all with particularly impressed with the administrators do not need extended delegation and tool’s ease of use, power and extensive technical skills auditing capacities,” comments speed of deployment. or training, which enhances Jesús Mª Álvarez Ruiz, Systems productivity. And delegating Engineer, Universidad de la Rioja. “Active Roles has enabled us to administration of resources “We also needed a customizable deliver important functionalities to the resource owners—who AD management web console— to network administration, understand better than IT who functionality that was missing in without the user being affected needs access—makes systems the native environment.” or the need for additional function more effectively. An easy-to-use web that deliver greater value to the interface means no organization.“ technical training is required Detailed auditing “Before deployment of Active enhances security and Roles, all assignment of ensures accountability members to groups and all assignment of permissions Moreover, with Active Roles, in AD had to go through us, the university can audit in the Microcomputing and User detail 100 percent all the Service,” explains Álvarez. “Now, tasks performed on Active once the solution is deployed Directory, enhancing security via a webpage, the delegated by ensuring accountability for administrators can keep users all administrators. Finally, the updated and assign permissions university credits the automation independently, without needing provided by Active Roles with technical knowledge. We can reducing human errors, which also create groups based on has also helped enhance system user attributes, which was not performance for users. possible previously.” About One Identity Granular delegation of administrative rights frees The One Identity family of up highly skilled IT staff identity and access management (IAM) solutions, offers IAM Delegating specific for the real world including administrative rights to help business-centric, modular and desk operators and others integrated, and future-ready has freed more highly skilled solutions for identity governance, system administrators to work access management, and on more difficult projects privileged management. important to the university. “Thanks to Active Roles, systems Learn more: OneIdentity.com administrators no longer have to perform routine administrative tasks without any technical value,” explains Álvarez. “That enables them to focus on tasks

One Identity and the One Identity logo are trademarks of One Identity LLC. Other trademarks are property of their respective owners. Availability and terms of One Identity LLC, Solutions and Services vary by region. This case study is for informational purposes only. One Identity LLC makes no warranties – express or implied—in this case study. © 2013 One Identity LLC. All Rights Reserved.