Profile

CommunityPlatform_1350x900.jpg

BRIAN ARKILLS

Edit My Profile


My Content

1 to 7 of 7 total
Posted By BRIAN ARKILLS 11-28-2023 10:06:36 AM
Found In Egroup: Identity and Access Management
\ view thread
To reinforce Richard's "best practice is to never reassign" statement: "Subscriber identifiers SHOULD NOT be reused for a different subject" https://pages.nist.gov/800-63-3/sp800-63b.html "user identifier is a persistent, non-reassigned, non-targeted identifier" https://refeds.org/category/research-and-scholarship ...
Posted By BRIAN ARKILLS 04-26-2023 05:07:56 PM
Found In Egroup: Identity and Access Management
\ view thread
No, we don't separate the mailboxes for an individual based on their student affiliation or employee affiliation. The advice I'd give for your situation is to give management an estimated price tag that goes along with their desired outcome. You could also discuss DLP as an alternate solution, with ...
Posted By BRIAN ARKILLS 04-25-2023 05:16:19 PM
Found In Egroup: Identity and Access Management
\ view thread
Student affiliation is retained for 2 quarters past an active course load (note: summer quarter doesn't count for the purposes of this calculation), with an email notification 2 weeks prior to loss of entitlements. The number of entitlements that a student affiliation provides is too onerous to list ...
Posted By BRIAN ARKILLS 09-15-2022 09:42:33 AM
Found In Egroup: Identity and Access Management
\ view thread
I wonder if the issue is tied to the Outlook Zoom plug-in version when it was installed. During our legacy authentication project, we discovered that people who enabled the Calendar and Contacts Service in Zoom prior to version 4.6.8 were likely still using legacy auth. Removing and re-adding (with a ...
Posted By BRIAN ARKILLS 08-19-2022 10:24:31 AM
Found In Egroup: Identity and Access Management
\ view thread
If you are using Azure MFA, then you are licensed for Conditional Access. With conditional access you can specify a wide variety of conditions as exceptions to a general policy that requires MFA. For example, network location can be an exception-if someone is using a computer in a hospital operating ...
Posted By BRIAN ARKILLS 08-01-2022 10:44:28 AM
Found In Egroup: Identity and Access Management
\ view thread
https://itconnect.uw.edu/wares/msinf/design/users/inactive-users/ covers our policy/practice for our Microsoft accounts. We haven't yet adopted a policy/practice at the NetID level above that, but it is in our roadmap to do so. We may revisit the time periods involved when we shift to enforcing this ...
Posted By BRIAN ARKILLS 02-01-2022 12:03:47 PM
Found In Egroup: Identity and Access Management
\ view thread
Should be possible based on the URL you sent. The line item entitled: "Set up SSO using a third-party IdP with Google as a service provider" says it is possible with both free & premium. The meaning behind that phrase is that the Google IdP trusts your local IdP for federated sign ins to your Google ...