Profile

CommunityPlatform_1350x900.jpg

Richard Frovarp

Edit My Profile


My Content

1 to 8 of 8 total
Posted By Richard Frovarp 11-28-2023 08:57:54 AM
Found In Egroup: Identity and Access Management
\ view thread
Entra and AD Object identifiers are implementation specific. They may or may not survive a restore. And if you delete the account, it isn't persistent. We use a name based ePPN, a SIS/HCM identifier, and an IAM specific identifier. The IAM specific identifier is what goes out everywhere it can. It ...
Posted By Richard Frovarp 12-05-2022 09:46:32 AM
Found In Egroup: Identity and Access Management
\ view thread
I would agree with the idea of going with a policy. If you have multiple accounts, then each system sending email has to be setup to send to the right location. And perhaps more importantly, you have to train all of your users on how to choose which email address to send to. They likely respond to the ...
Posted By Richard Frovarp 11-01-2022 08:50:12 AM
Found In Egroup: Identity and Access Management
\ view thread
Doesn't look like dates have been updated recently. Local Enterprise was set for last June, with medium/strong coming at the end of the year. Not all parts of the NIH will require this, as it is risk based depending on the service being accessed. https://auth.nih.gov/CertAuthV3/forms/help/compliancecheckhelp.html ...
Posted By Richard Frovarp 10-07-2022 12:27:29 PM
Found In Egroup: Identity and Access Management
\ view thread
Well, you bring up a good point. I think the hope is that where it matters, access for employees will be cleaned up. Certainly on our own local systems that happens by the IAM system automatically. I at least partially assume that the more removed from us such a system is, hopefully the less sensitive ...
Posted By Richard Frovarp 10-03-2022 03:24:36 PM
Found In Egroup: Identity and Access Management
\ view thread
At North Dakota State University, we do not reassign usernames. Once they are used, they are used. It is generally a bad idea to reassign, and it appears to be getting worse. You don't quite know what remote system you are federating to that might not correctly revoke access or delete historic data ...
Posted By Richard Frovarp 05-31-2022 01:06:31 PM
Found In Egroup: Identity and Access Management
\ view thread
We don't have the scheme you are talking about. However, given what we do have, people are confused as to what their username or email address is. We're in a shared O365 tenant at the university system level. The username is the same, but the domain is different. So people frequently think that their ...
Posted By Richard Frovarp 02-28-2022 10:16:54 AM
Found In Egroup: Identity and Access Management
\ view thread
We have an open position in the Enterprise Application Development group in the Division of IT at North Dakota State University. This position will focus on IAM and data processing. We use the InCommon Trusted Access Platform components of Grouper, midPoint, COmanage, Shibboleth. We also use CAS. We ...
Posted By Richard Frovarp 12-14-2021 01:23:31 PM
Found In Egroup: Identity and Access Management
\ view thread
The advantage of a Yubikey is that it can be used for more things. Users can use it for other services, and it is ready for you to use in the future for a passwordless service when you get there and/or your users start using something like that.