Sharing below questionnaire helping partners and customers designing identity based security.
Identity based security is not a feature - it is an architecture. We need to map users/machines to IP addresses and this mapping must be shared across the network. The mapping needs to fulfil the needs of the user to application communication.
This concept is outlined in sk170765. The below questionnaire accompanies the planning of this architecture.
- How many users are working with how many applications?
- How many gateways are securing these applications?
- What’s the number of Active Directory domains and their trust?
- How many Logon Servers do we have per location/logical area/business unit?
- What’s the average number of groups a user belongs to?
- Are there nested groups?
- Is a Global Catalog used?
- How to share Identity Sessions?