Loading...

Automate provisioning and governance of your on-premises applications

Automate provisioning and governance of your on-premises applications

I’m excited to announce the general availability of provisioning to on-premises applications using Microsoft Entra Identity Governance. You can now automate provisioning and manage the lifecycle of users in on-premises applications, without requiring any custom code.    

 

Many of you are already using Microsoft Entra Identity Governance to easily provision identities into hundreds of SaaS applications using the built-in connectors. You can now provision identities from Azure Active Directory (Azure AD) directly into on-premises applications that rely on user identities stored in a SQL database, LDAP directory (other than Active Directory Domain Services) or support the SCIM standard for provisioningThis means you can use Microsoft Entra Identity Governance to govern access to on-premises applications with out-of-the-box on-premises connectors and no custom coding required! 

 

Let’s walk through an example of how an organization, Contoso, uses Microsoft Entra Identity Governance to provide access to an on-prem application that manages critical manufacturing processes. The application is deeply embedded in the organization and has been around for years. It doesn’t support modern SCIM APIs for user management, but it does rely on an OpenLDAP server to manage user access. With Microsoft Entra Identity Governance, Contoso can:  

 

  • Increase employee productivity by automating application access. 
  • Manage costs by deploying a cloud-based provisioning solution. 
  • Manage risk by periodically reviewing and revoking access. 

 

 

Contoso governs access to an on-premises manufacturing app that relies on OpenLDAP as a user store.Contoso governs access to an on-premises manufacturing app that relies on OpenLDAP as a user store.

 

 

In three easy steps, the admins at Contoso enable users to access on-premises applications, while ensuring the necessary governance processes are in place: 

 

1. Configure application access 

 

When employees join the organization, they are marked as hired in Workday and have an account automatically provisioned in Azure AD. The administrators have configured an access package with entitlement management. When a new employee in the manufacturing department is hired, they are automatically assigned access to the manufacturing app through the access package. When employees leave, or change jobs, their assignment is automatically removed, so they can no longer access that application.  

 

There are some users that need time-limited access to the manufacturing app that aren’t in the manufacturing department. To accommodate this requirement, the admins at Contoso have a second policy that allows other employees to request access to the application via an access package. 

 

All users that need access are either automatically granted access or can self-service request the access they need. 

 

SHDriggers_1-1674829565102.png

 

 

 

SHDriggers_2-1674829565107.png

 

 

2. Automate provisioning accounts 

 

The manufacturing app is on-premises and doesn’t support modern standards such as SCIM, but it does have an OpenLDAP server used for access control. The administrators use the generic LDAP connector that Azure AD provides and sets up provisioning. Users that are granted access to the manufacturing application through an access package automatically have accounts provisioned.   

 

The admins at Contoso can take advantage of the out of the box LDAP connector and automate provisioning, without needing to modernize their application. 

 

SHDriggers_4-1674829565112.png

 

3. Periodically review and certify access 

 

The manufacturing app has business critical data and Contoso is required as part of compliance processes to ask employees outside of the manufacturing department to regularly confirm that they need access and provide a justification. The administrators of Contoso set up a multi-stage access review of non-manufacturing users that have access to the app. First, the employee self-attests to requiring access, and then the review is transferred to the application owner for final approval.  Users that do not complete the access review are automatically removed from the application. 

 

Internal and external audit requirements are satisfied as the right access controls and reviews are in place and the “why” access exists can be proven. 

 

 

SHDriggers_5-1674829565115.png

 

 

Together with Azure AD’s entitlement management, provisioning, and access review capabilities, Contoso is able to provide access to both SaaS and on-premises applications while ensuring governance and security requirements are met. Go enable this new capability today and start governing access to on-prem applications in the same way you do your SaaS applications. 

  

This is just the beginning of on-premises support from Microsoft Entra Identity Governance. We’ll continue to invest more, including the ability to provision using PowerShell, Web Services, and other custom connectors to line of business applications so that customers using Microsoft Identity Manager (MIM) can migrate their provisioning capabilities to Microsoft Entra Identity Governance.

 

We love hearing from you, so share your feedback on these new features through the Azure forum or by tagging @AzureAD on Twitter.  

 

 

Joseph Dadzie, Partner Director Product Management

Twitter: @joe_dadzie

LinkedIn: @joedadzie

 

 

Learn more about Microsoft identity: 

Published on:

Learn more
Azure Active Directory Identity Blog articles
Azure Active Directory Identity Blog articles

Azure Active Directory Identity Blog articles

Share post:

Related posts

Sync identities from Rippling to Microsoft Entra ID

Today, we’re thrilled to announce that customers using Rippling HCM can now automatically provision users to on-premises Active Directory and ...

1 year ago

Microsoft Entra ID Governance for government

I’m pleased to announce that as of November 1, 2024, Microsoft Entra ID Governance is available for federal agencies, state and local governme...

1 year ago

Update to security defaults

As part of the Secure Future Initiative, we’ve evolved our security approach to align with three security principles: secure by design, secure...

1 year ago

Meet Microsoft Entra at Ignite 2024: November 18-22

Microsoft Ignite is just around the corner, taking place from Monday, November 18, 2024 through Friday, November 22, 2024, in Chicago, Illinoi...

1 year ago

Manage Microsoft Entra ID role assignments with Microsoft Entra ID Governance

I’m excited to announce that we now support Microsoft Entra role assignments in Microsoft Entra ID Governance's Entitlement Management feature...

1 year ago

The latest enhancements in Microsoft Authenticator

Hi folks,   I'm thrilled to announce three major Microsoft Entra ID advancements that will help you protect your users with phishing-resi...

1 year ago

Microsoft Security announcements and demos at Authenticate 2024

The Microsoft Security team is excited to connect with you next week at Authenticate 2024 Conference, taking place October 14 to 16 in Carlsba...

1 year ago

What's new in Microsoft Entra - September 2024

We’re excited to announce the general availability of Microsoft Entra Suite—one of the industry’s most comprehensive secure access solutions f...

1 year ago

Explore the key benefits of Microsoft Entra Private Access

The traditional network security models are becoming increasingly ineffective in a world where remote work and cloud services are the norm. Co...

1 year ago

Join us at the Microsoft Entra Suite Showcase!

This fall, we are bringing the Microsoft Entra Suite Showcase to cities worldwide. Join us to explore how our latest advancements in secure id...

1 year ago

Newsletter

Get the latest Dynamics 365 and Power Platform content in your inbox

A curated digest of community blogs, product news, videos, and podcasts — delivered without the noise.

Weekly updates Unsubscribe anytime Fresh community picks
We use your email only for the newsletter and you can unsubscribe at any time.
By subscribing, you agree to the privacy policy.