This session is for members.

Subscribe or log in to watch every GoSec session.

Subscribe Log in

This recording is not available yet.

Application integration patterns to fast track Identity and Access Management compliance objectives

Download resources

About this session

Sebastien Gagne, an Identity Solution Architect at Indigo Consulting, presents pragmatic ways to onboard secondary applications into an IGA platform faster than building a custom, bidirectional connector for each one. His first strategy is reusing what already aggregates access data, such as an asset/inventory manager or a central directory like Entra ID, either as a one-way extract with a manual closed-loop request process or, where group membership already drives SSO, as a full bidirectional integration. His second strategy pushes standardization onto application owners: a simple CSV format, a standardized database view, or SCIM as a REST exchange contract, so each application team does its own analysis in parallel instead of the IGA team reverse-engineering every schema. His third strategy trains platform admins and directory specialists to generate new connectors from a template so integrators are freed for genuinely complex work. His fourth is a proxy application manager for systems that cannot be integrated at all or are too low-volume to justify it, holding a manual, periodically reconciled copy of accounts and access. He closes by stressing that none of this works without clear governance objectives and executive backing.

With a large application ecosystem, it can be a challenge to integrate all that is required by your compliance requirements. As an IAM leader, you want to have a clear and complete view of your identity security posture in a timely manner. Knowing that integrating with each and every application is time and resource consuming, this presentation will go over some patterns, strategies and tips to help you and your team get to the finish line faster and be able to apply your governance rules.

Key takeaways

  • Check for systems that already aggregate access data (asset manager, CMDB, central directory) before building a custom connector; connecting there first gives fast, broad visibility.
  • Push data standardization onto application teams by requiring a simple CSV export, a standardized database view, or a SCIM interface, rather than having the IGA team analyze every application's schema.
  • Train platform admins or directory specialists (e.g. an Entra ID owner handling all SSO/SCIM integrations) to generate new connectors from a proven template, freeing integrators for genuinely complex cases.
  • For applications that truly cannot be integrated or have too few accounts to justify it, use a proxy application manager holding a manually reconciled copy of accounts and access, refreshed on a fixed schedule to catch drift.
  • Treat governance objectives and executive sponsorship as prerequisites, not add-ons; without them there is no justification for the resourcing these integration strategies require.

Speakers

Sebastien Gagne
Sebastien Gagne
IAM Expert · Indigo Consulting
Sébastien Gagné is an IAM Architect at Indigo Consulting for multiple years. With more than 10 years of experience in the Identity and Access Management (IAM) world, he has delivered many solutions from multiple vendors (ForgeRock, Sailpoint, etc)… Read moreRead less

Sébastien Gagné is an IAM Architect at Indigo Consulting for multiple years. With more than 10 years of experience in the Identity and Access Management (IAM) world, he has delivered many solutions from multiple vendors (ForgeRock, Sailpoint, etc). He also has played multiple roles from integrator, to analyst, ending with architect, making him suited to talk at multiple levels of details and with a varied audience. Sébastien has a bachelor and a master in Software Engineering, as well as multiple certifications (CISSP, CIDPRO, and vendors).

Resources

Tags

More from GoSec 2024

Also from Sebastien Gagne

On the same topic

This site is registered on wpml.org as a development site. Switch to a production site key to remove this banner.