4 ms·
well you mentioned the system only adds the account to a group in AD, if i am not wrong Azure directories work for cloud based platform, and also it requires t
by daemon_9009 3y ago
well you mentioned the system only adds the account to a group in AD, if i am not wrong Azure directories work for cloud based platform, and also it requires the company to use their own domain for sso, AD is now Entra ID. But what about the permissions that AD dont cover like github, jira, database access?
- stop50 3y agoJira and bitbucket are also integrated in the AD groups, the access to servers is provided through an server in the middle for root users and an obscure pam module provides access to non-root users.
- daemon_9009 3y agois AD single point contact or multi point approval system, can people in between approve the requests? and can the tickets be raised for a certain permission? can that permission be tracked? i think AD is merely a portal for azure and other cloud platforms.
- stop50 3y agoAD is the source of truth that is changed updated by the permission system. The permission system tracks the progress and the people who approve it.im merly a user of it and i can say that an absolute minority of applications don't use the AD for authentication.
- daemon_9009 3y agoso is it safe to beleive that AD is multi-point approval system, almost for all applications, and tickets can be raised using it? So that means making another platform is rather obsolete, isn't? Also I have never used AD but reading its docs i came to know that, for using sso the company has to use the domain provided by the AD, like yourcompanyname@microsoft.com, what company will want its users to sign in using this kind of a domain?
- stop50 3y agoAd is an extension omtop of ldap.using the kerberos like usernames is possible, but most systems accept the username, since there are no conflicts with the usernames.