Home / FAQs / Business information selection, integration and data governance
QUESTION & ANSWER

Enterprise SSO Need

The SSOs do not have the same rights for all users and the business authorization is still controlled by the system. The enterprise also plans the account life cycle, multiple factor certification, separation recovery and emergency login.

Answer the question.

First, give conclusions that can be used for decision-making

The SSO addresses “Who You are” and how you log in, and the operating system remains responsible for “what you can do”. Common agreements include ODS, Outlook 2.0 and SAML, and older systems may need gateways or matching.

DECISION FACTORS

What conditions need to be identified before judgement is made?

The same question may have different answers under different business, data and project phases. It is suggested that the following conditions be checked and that the common findings on the web be incorporated into their own projects.

Number of systems, type of user and level of account repetitionStatus of existing systems supporting ODS, SAML or other agreementsMultifactor Certification, Terminal, Network and Compliance RequirementsSource of identity, organizational synchronization, separation and temporary account processes
ACTION STEPS

Suggested order of advance

01

First, we'll be clear about the target and the border.

Take an inventory of the status of sources, applications, protocols, account numbers and privileges.

02

Validation Key Dependence

Establish uniform marking, certification strategies and system access standards.

03

Development of assessable outcomes

Access low-risk applications and validate login, exit and recovery.

04

Make sure you decide the next step with the real results.

(b) The transfer of the core system in batches and the establishment of a monitoring and emergency account number.

PRACTICAL EXAMPLE

How do you understand it in the actual business?

Example used to illustrate the method of judgement

After the separation of an employee, changes in the status of the HR system can trigger a uniform identity ban and inform the business systems of the recovery of conversations and privileges. If only login jumps without a life cycle synchronization, the legacy account risk remains.

COMMON RISKS

The easiest pit to step on.

Misunderstanding SSO as a unified operational mandate

Only login achieved, no exits, separations and token lapses processed

No emergency visit programme in case of an identity platform malfunction

ACCEPTANCE

How should we end up receiving and confirming?

Receiving and inspection is to cover login, exit, multiple factors, account synchronization, disablement, cross-organizational, external users, audit and downgrading of failures, and to confirm that the operations systems still perform their minimum authority.

When preparing to communicate with suppliers or internal teams, it is recommended that current processes, representative samples, existing systems, planning time and budget levels be brought. First, the unknown items are clearly marked, and then the decision is made to use diagnostics, PoC, fixed-range projects or ongoing research and development, which is usually more reliable than a direct demand for a price and duration without borders.

Your project conditions are different from the examples above?

Operational objectives, existing systems, sample and planned time could be collated before consultants could make preliminary judgements in relation to actual boundaries.

Associate project consultants