Skip to content
PERINGER Data Solutions, back to home

Back

Solution

Identity, directory and access

Many incidents run on a valid account whose password was stolen, or on an account holding too many rights. I design the directory, Active Directory or Entra ID for instance, connect the compatible applications, carry every right through a group that names a role, put technical keys and passwords in a vault, and verify that a departure closes every access.

The gains from a directory kept in order

In practice

  • Directory design or takeover: Active Directory, Entra ID or Google Workspace as the source of record, with compatible applications federated through SAML or OpenID Connect
  • Group architecture: groups that describe people, groups that describe rights, and the first feeding the second
  • Multi-factor authentication applied first to privileged accounts and remote access, with a recovery method matched to the risk
  • A joiner, mover and leaver procedure, with the list of rights granted, retained and removed
  • Privileged accounts separated from everyday accounts, and a sealed break-glass account for the day the directory itself is down
  • A secrets manager for technical passwords, API keys and certificates, with an owner, a rotation date and scanning for secrets left in code
  • An access review scheduled by risk, with an owner, an exception list and a transferable procedure

Systems involved

  • Active Directory, Microsoft Entra ID, Google Workspace
  • SAML or OpenID Connect applications, code repositories and CI tooling
  • Secrets managers and team password vaults
  • FIDO2 keys and authenticator applications
  • Terraform to describe groups and roles in the cloud

Service lineServers and hosting →

How it runs

  1. Inventory

    Accounts, applications, shared access, service accounts and secrets are reconciled against the lists you have. Each gap gets a priority and an owner.

  2. Architecture

    I draw the groups and roles, then connect the applications to the directory one by one, keeping the old sign-in open until the new one is validated.

  3. Hardening

    Second factor and device conditions applied by risk, privileged accounts separated, secrets migrated into the vault and the emergency account tested.

  4. Handover

    Your team receives the joiner and leaver procedures, the review method, the map of connected applications and the secret-rotation procedure.

Test the fit: Identity, directory and access

Describe the context, constraints and decision you need to make. The first conversation qualifies scope, boundaries and the next useful step.

Describe the situation