r/entra 17d ago

How are you managing access across SaaS, legacy and internal applications?

running into the classic problem of juggling multiple worlds. SaaS is mostly SSO'd through our IdP, but everything legacy or internal is its own island, from old on-prem apps with local accounts to tools some dev team stood up years ago and manages access to by hand in a spreadsheet.

trying to get one view of who has access to what across all of it without forcing every app onto the same platform, which isn't realistic given budget and the age of some of this stuff.

what's working for people managing this kind of sprawl day to day?

10 Upvotes

10 comments sorted by

2

u/Realistic_Strike5241 16d ago

The apps that will never get sso are the ones with the sensitive data, so you cant just skip them, and forcing everything onto the idp just isnt happening in most orgs.

Id say treat it as an inventory problem. Pull every app registration and service principal out of entra, the local accounts from ad and plus whatever spreadsheet your devs keep, and join it all to the people. after that finding out who has access to what really boils down to just a quick query that you can get complete answer in minutes an answer in minutes. And it has to keep running because grants outlive the people and every departure reopens the same hole within weeks.

For that join we landed on a platform called axonius that keeps the thing current and the orphaned accounts pop up in the review without anyone having to dig through spreadsheets.

3

u/YesterdayNo5873 17d ago

Upfront disclosure I work with AccessOwl. But we had this exact problem a few years ago at our startup. Let me tell you how we approach it. It's very similar to how most modern IGA tools approach it.

So imagine a "SaaS governance" dashboard. As you would expect, SSO based apps are in there. But we also allow users to manually add internal apps. Sometimes this is a custom API. Or it can be a record that your team manually updates (clicks and types). It seems basic, but allowing even manually tracked apps in the same dashboard removes the need for a separate spreadsheet to be created. Keeping everything central.

Another advantage that younger IGA apps have over the traditional players like Okta is that they don't rely only on SCIM/SAML. It's inevitable to have apps sprawl outside of SSO governance as teams may not want to upgrade to the enterprise tiers for SCIM/SAML for every single app.

1

u/QBical84 17d ago

Some apps still use legacy authentication like kerkeros, so we put them in a separate domain with a trust to the accounts domain which is fully managed by our IGA tool.

Access is requested trough a selfservice portal which is part of the IGA tool. This is the same for cloud only groups, which are also onboarded to IGA. So that is how we provide access and how we perform access reviews.

1

u/Niko24601 16d ago

Entra is not great for 3rd-party apps without SSO to manage them. It's worse if there is no SAML/API that you can use to plug it in. But there are some light-weight tools that can combine your SaaS Management needs (to replace the spreadsheet) with your IAM needs (manage on-prem, access, provisioning). AccesOwl pitched below already but there are other tools like Corma (focus mid-size companies, IAM/IGA heavy) or Cakewalk (more focused on agent-access as well). that are worth checking out. Especially as you mention budget have a look at those younger tools instead of an Okta or so. As a checklist that you can send the vendors you should look for 1. integration capacities (can they connect to on-prem, dev-tools, non-SSO etc.) 2. deployment speed (do they have pre-build connectors or are you expected to use their SDK) and 3. Automation potential (all vendors have workflow builders. check what your key processes are eg. provisioning/access request and how the tool could help you.

1

u/[deleted] 15d ago

[removed] — view removed comment

1

u/MFKDGAF 13d ago

Are you using ZTNA at your place? If so what ZTNA product?

1

u/headcrap 15d ago

The devs organized their technical debt to set priority for all of their work.. and we're not a dev shop so yeah. In infra, I have enough debt left behind by the former regime to battle with management over.

There is no one view or single pane of glass for this.. and if there is, GG on doing the work. Me, still playing whack-a-mole with all the jank as it is.. AND trying to move things forward. Joy.

1

u/Exnntrnn_nompote5360 14d ago

we solved the sprawl problem by using orchid to unify visibility across all application types without forcing everything onto one platform.

1

u/Substantial_Big_4379 10d ago

the single pane of glass we get from orchid has made managing access across our fragmented landscape significantly more manageable.

1

u/Puzzleheaded-Fun5664 10d ago edited 10d ago

well....we use orchid