Showing posts with label News. Show all posts
Showing posts with label News. Show all posts

Wednesday, July 22, 2015

My favorite Centrify features for the last year (2014-2015)....

Background

With the release of Centrify Server Suite 2015.1 and Cloud (CIS/CPS) 15.6 we have wrapped up another great year of introducing great capabilities to keep our existing customers happy and to help them solve the challenges of today and tomorrow.

I am biased towards functionality that help existing customers optimize their existing deployments, and in this article I will outline my personal top 10 Centrify features that promote operational efficiency for existing Centrify Server Suite or Centrify Identity/Privilege Service customers.


Finally, this would not be possible without product management that listens attentively and tries to understand our use cases plus our amazing engineering team.  This is a very exciting time to be at Centrify.


1. UNIX/Linux/Mac Agent:  Enhancements to adjoin
Top10 - Enhancements to adjoin.jpg
Release date:  Apple Scheme (2014.1); ComputerRole (2015.1)
What is it:  Facilitate OS X Migrations and optimize your automation scripts
How does it improve Operational Efficiency:  When an existing OS X user moves from the Apple Directory Services plugin, extra steps eliminated.  Reduced size of provisioning scripts for servers (Chef recipes, Puppet scripts).
What do I need to do to get the benefits: Upgrade to 2015.1 (5.2.3.x).

2. Identity Service: Application Provisioning
Top10 - CIS App Provisioning.jpg
Release date:  Preview started in April 2014 for Box, GoogleApps, Office 365, Salesforce and ZenDesk
What is it:  Just add a user (or remove) to an AD group or CIS role, and the user will get provisioned (or deprovisioned), the proper license is applied and if supported, the proper role is assigned as well.
How does it improve Operational Efficiency:  Use the normal cadence of group management and extend it to be the hub for your App provisioning and effective controls to disable access timely and control costs.
What do I need to do to get the benefits: Use the App Catalog and find apps ready for provisioning.

3. DirectAudit: Performance and Scalability Improvements for Enteprise Edition
Top10 - DA Enhancements.jpg
Release date:  July 2015 (Server Suite Enterprise Edition 2015.1)
What is it:  Centrify invested significant development cycles to optimize all components of DirectAudit
How does it improve Operational Efficiency:  Scalability, right-sizing, better compression, better optimization, this all translates in less effort to maintain DirectAudit deployments.
What do I need to do to get the benefits: Upgrade to 2015.1 DirectAudit.

4. Manageability: PowerShell Management for Centrify DirectManage and DirectAudit
Top10 - PowerShell.jpg
Release date:  DirectManage (Server Suite 2014), DirectAudit (Server Suite 2015)
What is it:  Windows PowerShell to automate/orchestrate Access and Audit capabilities
How does it improve Operational Efficiency:  The tasks traditionally performed in the DirectControl and DirectAudit MMCs now can be scripted, automated and orchestrated by leveraging PowerShell.  All PowerShell commandlets leverage the DirectManage or DirectAudit APIs.
What do I need to do to get the benefits: Install the PowerShell Modules for your platform.

5. Windows PIM:  SmartCard Support for Windows Privilege Elevation
Top10 - DZWin Multifactor.jpg
Release:  Server Suite 2015
What is it:  In high-security environments, when a privileged AD user uses Centrify to perform Windows Privilege Elevation, the user can be prompted  for the smartcard PIN.
How does it improve Operational Efficiency:  By eliminating "-a" accounts and forcing Windows users to use privilege elevation, you are doing the proper due-diligence to limit the impact of advanced threats.
What do I need to do to get the benefits: Upgrade to Server Suite 2015 (3.2.x)

6. Kerberos:  Infinite Kerberos Ticket Renewal
Top10 - Infinite Kerberos Ticket.jpg
Release date:  Server Suite 2015.1 (July 2015)
What is it:  Kerberos tickets expire, but there are applications (e.g. Hadoop) that require jobs or credentials to be effective longer than the policy define din AD.  These parameters and GPOs allow the UNIX agent to trigger a renewal based on AD principal (user or group).
How does it improve Operational Efficiency:  Improves the supportability of these use cases.
What do I need to do to get the benefits: Upgrade to Server Suite 2015.1 (5.2.3.x)

7. LDAP Proxy:   Support for TLS and Startup Scripts
Top10 - TLS Support added to LDAPProxy.jpg
Release date:  Server Suite 2015 (March 2015)
What is it:  Secure communications for our very useful LDAP Proxy.
How does it improve Operational Efficiency:  Several apps and appliances only support LDAPS, in addition, now there's no need to do manual scripts to startup the slapd daemon.
What do I need to do to get the benefits: Upgrade to Server Suite 2015 (5.2.3.x)

8. Mac Agent:  AD + Identity Service Combo Join
Top 10 - OS X Combo Join.jpg
Release date:  Server Suite 2014.1 and CIS
What is it:  Macs in the enterprise are on the move and multiplying.  Not only they need to be managed from AD to get unified identity, but being able to provide Enterprise Manageability and Self-Service.
How does it improve Operational Efficiency:  Now you can empower your mobile Mac workforce with capabilities while decreasing calls to the help desk, this goes along with their existing iOS, Android or Windows devices.
What do I need to do to get the benefits: Enroll your Macs now using Identity Service.  Just go to the Devices tab.

9. Identity Service:  App Gateway  (Per-app VPN, Secure Access)
Top10 - CIS App Gateway.jpg
Release date:  Beta in 2014, live January 2015
What is it:  App gateway eliminates the need to establish a persistent VPN to access an application or a resource (server, appliance)
How does it improve Operational Efficiency:  Eliminate the need for VPN access for external users  (consultants, external partners) for both apps and servers.
What do I need to do to get the benefits: Get Centrify Identity Suite App Edition

10. Identity Platform:  Centrify Privilege Service
Station - Portal Mixed.JPG

CPS - Password Checkout.jpgMobile - Password Checkout.jpg
Release date:  May 2015
What is it:  Shared account password management (SAPM), secure remote access, privileged session monitoring (PSM), mobile-ready, deploy anywhere.
How does it improve Operational Efficiency:  Built on the Identity Platform, complements Server Suite by providing SAPM and PSM plus more!
What do I need to do to get the benefits: Request a trial now!

This is a copy of a featured article written in the Centrify Community.

Tuesday, June 16, 2015

Centrify Identity Platform - Making Strides and Taking Names

Centrify Identity Platform consists of two products:  Identity Service and Privileged Service

Centrify Identity Service (formerly User Suite) has continued its meteoric rise and I want to congratulate many of my coworkers on their hard work and dedication.

In the past two weeks, to major publications have continued to highlight its critical acclaim:
  • 2015 Gartner Magic Quadrant for Identity and Access Management as a Service
    • Positions Centrify as a visionary, proving and validating the completeness of the vision that combines On-Prem/SaaS SSO with Enterprise Mobility Management plus robust policy, Multi-factor Authentication and VPN-less Access.
    • Ranks #3 among the solutions in a year that saw Salesforce, IBM and Microsoft enter the market and continues to beat the leader in execution and completeness of vision (#2 in pure play).  It's only a matter of time given Centrify's leadership.
    • This is all looking at data from last year!!!!  This is before App Gateway, Privileged Service, ServiceNOW integration and others were ready to go.
      Get the report here.
  • Network World Names Centrify Identity Service the best SSO tool for 2015
    • Calls out the integration of SSO+EMM+MFA+Management interface.  Everyone else left to eat the dust.
Centrify Privileged Service (CPS) is a new entry (announcement) to the hybrid family of products that has a pure play in two areas (and growing):  Shared Account Password Management (SAPM) and Secure Remote Access, but it builds on the existing capabilities of the Identity Service to deliver complementary capabilities to Server Suite.

RBAC continues to be the preferred method for Privileged Account Management (PAM), however, for emergency, one offs and change control, using a shared privileged account can be useful.  Here's a video that illustrates the differences between the approaches:



Capabilities of CPS

Shared Account Password Management
Use your AD account and Multi-factor authentication to check out UNIX, Linux or Windows accounts, enforce policy, access anywhere (centrally or via mobile app).  Upon check-out, the password is rotated for you.

Mobile - Password Checkout.jpgCPS - Password Checkout.jpg

Secure Remote Access
Leverage the existing cloud connector infrastructure to deliver secure remote access to resources regardless of their location (on premises or in the cloud IaaS).  
Apps, UNIX, Linux and Windows sessions can be presented to users in a cohesive way

Much more to come, and many synergies with Server Suite


Very exciting time to be at Centrify and especially to help out prospects and existing customers.

Friday, August 29, 2014

Begin Synergy: Suite 2014.1 is here!

I'm very excited about the new update to Centrify Suite 2014.  This is a maintenance update that brings in support for RHEL7 and Debian 7.5, 7.6 and derivatives of these popular platforms. It includes additional updates, but what really makes it exciting to me is a feature available in the agent for Mac OS X called Combo Join.

Combo join marks an interesting milestone that affects this blog.  The merging of Centrify on-premise and Cloud offerings.  Combo join addresses the needs of employees with the top-of-line AD integration and Bring Your Own Mac Scenarios for third parties (like contractors or partners).

A simple check-box = more management capabilities

Combo-join means having the ability to register a Mac both as an AD domain member and with the Centrify Cloud Service.  This allows for two management possibilities:

  • The AD Group Policy-based Centrify agent GPOs (400+)
  • The Centrify Cloud Service policies that can be delivered via GPOs or via the cloud.
Architecturally they are different, one uses the mappers and the other users profile manager.  Combo join is a simple check-box that extends the AD Join assistant:

Once joined to the cloud service, a profile is delivered that permits management via the cloud:


This means that now both IT and end-users (via the Centrify User Portal) can perform device management along with their iOS and Android devices and IT will be able to deliver configuration management in a different vehicle without requiring a hard domain join.

Users will be able to perform self-service device management
IT will have more flexibility delivering configuration management

Why is this a game changer?

From this point on, we need to include Centrify User Suite content in this blog and if I'm correct, this is just the beginning.  Part of the reason why Centrify solutions are so easy to implement and are so cohesive is because they are developed in-house.  Not having to deal with Frankenstein-like solution packages like some of the traditional vendors translates into faster deployments and an easier learning curve.
 
Expect a Cloud section with info about Server Suite plus sections on synergy between Mac, Server and User Suites.