<?xml version="1.0" encoding="utf-8" standalone="yes"?><feed xmlns="http://www.w3.org/2005/Atom"><title>Orphan Account on Sinetris's viewpoints</title><id>https://sinetris.info/tags/orphan-account/</id><link href="https://sinetris.info/tags/orphan-account/index.atom.xml" rel="self" type="application/atom+xml" hreflang="en" title="Orphan Account on Sinetris's viewpoints"/><link href="https://sinetris.info/tags/orphan-account/" rel="alternate" type="text/html" hreflang="en" title="Orphan Account on Sinetris's viewpoints"/><link href="https://sinetris.info/tags/orphan-account/index.atom.xml" rel="alternate" type="application/atom+xml" hreflang="en" title="Orphan Account on Sinetris's viewpoints"/><link href="https://sinetris.info/tags/orphan-account/index.rss.xml" rel="alternate" type="application/rss+xml" hreflang="en" title="Orphan Account on Sinetris's viewpoints"/><subtitle>Recent content in Orphan Account on Sinetris's viewpoints</subtitle><generator uri="https://github.com/sinetris/sine-die/">Sine Die theme for Hugo</generator><author><name>Duilio Ruggiero</name><email>duilio@sinetris.info</email></author><rights type="html">&amp;copy; 2023 - 2026, Duilio Ruggiero</rights><updated>2023-07-16T18:20:00Z</updated><entry><title>Advices</title><link href="https://sinetris.info/topics/iam/iga/considerations/" rel="alternate" type="text/html" hreflang="en" title="Orphan Account on Sinetris's viewpoints"/><content src="https://sinetris.info/topics/iam/iga/considerations/" type="text/html"/><published>2023-07-16T18:20:00+00:00</published><updated>2023-07-16T18:20:00Z</updated><id>https://sinetris.info/topics/iam/iga/considerations/#atom</id><summary type="html">&lt;h2 id="assets-and-people"&gt;Assets and people&lt;/h2&gt;
&lt;p&gt;Ensure to have proper Orphan Account Monitoring (for example, people leaving the
company) and delegation (for example, people in sick or parental leave) for people
assigned to managing assets (Asset Owners, Application Administrators, Infrastructure
Administrators, etc).
Take into consideration that people might be out of office because in vacation,
out sick, at a conference, etc.&lt;/p&gt;</summary><category term="/types/topic" label="type: topic"/><category term="/categories/iam" label="category: IAM"/><category term="/categories/iga" label="category: IGA"/><category term="/tags/orphan-account" label="tag: Orphan Account"/></entry><entry><title>Identity Security</title><link href="https://sinetris.info/topics/iam/iga/identity-security/" rel="alternate" type="text/html" hreflang="en" title="Orphan Account on Sinetris's viewpoints"/><content src="https://sinetris.info/topics/iam/iga/identity-security/" type="text/html"/><published>2023-07-16T18:20:00+00:00</published><updated>2023-07-16T18:20:00Z</updated><id>https://sinetris.info/topics/iam/iga/identity-security/#atom</id><summary type="html">&lt;h2 id="orphan-account-monitoring"&gt;Orphan Account Monitoring&lt;/h2&gt;
&lt;p&gt;It’s important to find missing identity associations or assets assigned to wrong identities (for example off-boarded employees).&lt;/p&gt;
&lt;p&gt;Examples:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;An account is associated to an asset but is not assigned to any identity&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;All accounts should be associated with one (and only one ) identity.&lt;/li&gt;
&lt;li&gt;If the system allow only one account (for example only one admin), access to that account should happen trough a system that keep track of all actions (see PAM and Just-in-time credentials).&lt;/li&gt;
&lt;li&gt;If credentials to the account are shared it will be hard to know who performed an action.&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Asset role (for example Owner or Admistrator) assigned to an Identity that left the company&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Employee assigned to a line manager that transferred to a different department&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="adaptive-authentication"&gt;Adaptive Authentication&lt;/h2&gt;
&lt;p&gt;Varying authentication methods based on runtime evaluation of risk factors.&lt;/p&gt;</summary><category term="/types/topic" label="type: topic"/><category term="/categories/iam" label="category: IAM"/><category term="/categories/iga" label="category: IGA"/><category term="/tags/orphan-account" label="tag: Orphan Account"/></entry></feed>