BeyondTrust

Security in Context: The BeyondTrust Blog

Welcome to Security in Context

Bringing you news and commentary on solutions and strategies for protecting critical IT infrastructure in the context of your business.

Complementing Privilege Identity Management (PIM) with the PowerBroker Management Suite

Posted February 28, 2012    Morgan Holm

While BeyondTrust has provided audit and recovery solutions for Active Directory for years, we are now seeing an increase in customer inquiries about Privilege Identity Management (PIM) challenges. This growing demand continues to be driven by security and compliance concerns and the need to prevent internal data breaches through the use of privileged accounts.

Active Directory continues to become more strategic in many organizations for the access it provides to applications and resources. From an identity perspective, Active Directory provides a central point for authorization and provisioning access. From a compliance perspective, understanding what applications and resources administrators access, what changes they make in Active Directory, Group Policy, and file resources is critical. And, it’s not only administrator accounts. It’s also users and groups that have elevated access to other sensitive information, which could be distributed throughout the organization. This includes sensitive information held within the numerous spreadsheets and other files scattered throughout the organization’s file servers.

From a PIM perspective, the PowerBroker Management Suite provides a foundation or “backstop” layer of visibility and control over administrator activity. This layer provides:

  • Central auditing, recording, monitoring and alerting of all actions for administrators and sensitive users/groups
  • A central view of all system administration activity
  • A reduction in the cost of forensic investigation
  • Faster response to security incidents, while improving the company’s ability to answer tough audit questions
  • Real-time alerting to ensure that unauthorized access to resources gets caught immediately
  • Real-time protection to ensure that unauthorized access to resources is prevented before damage is done
  • Data governance, which allows administrators to see who has/had access to resources in a timely and efficient manner
  • Unique audit logs, which are architected to support the “big data” security needs of today’s organizations, leveraging performance and storage optimization with data de-duplication that enables customers to collect and search millions of events within our online audit log
  • Workflow and approval controls for specific Active Directory management tasks for customers who do not implement change control systems, or in cases where the corporate change control systems do not cover the specific tasks required to manage specialized Windows and Active Directory tasks
Tags:
, ,

Leave a Reply

Additional articles

ovum-research

New Analyst SWOT Assessment Identifies Key Strengths of PowerBroker

Posted November 24, 2014    Scott Lang

Following on the heels of the Gartner PAM market guide and Frost & Sullivan review of Password Safe comes a new analyst review of our BeyondInsight and PowerBroker platforms, a SWOT assessment of BeyondTrust written by Ovum. Ovum’s honest and thorough review of BeyondTrust indicates that we are delivering, “…an integrated, one-stop approach to PAM….

Tags:
, , ,

Patented Windows privilege management brings you unmatched benefits

Posted November 24, 2014    Scott Lang

We are pleased to announce that BeyondTrust has been granted a new U.S. Patent (No. 8,850,549) for privilege management, validating our approach to helping our customers achieve least privilege in Windows environments. The methods and systems that we employ for controlling access to resources and privileges per process are unique to BeyondTrust PowerBroker for Windows….

Tags:
6

A Quick Look at MS14-068

Posted November 20, 2014    BeyondTrust Research Team

Microsoft recently released an out of band patch for Kerberos.  Taking a look at the Microsoft security bulletin, it seems like there is some kind of issue with Kerberos signatures related to tickets. Further information is available in the Microsoft SRD Blogpost So it looks like there is an issue with PAC signatures.  But what…

Tags:
, , , ,