Revised text for combined solution coming on Monday.

The Challenge

The enterprise-out approach is favored by organizations that are looking to leverage investments in policy logic residing with Microsoft AD, such as role definition expressed through group membership and entitlements, to manage access control to off-premises services and infrastructure.

Steve Coplan
Senior Analyst, The 451 Group

Security is the first order of business once a new cloud-based system spins up. Many systems deployed on public networks have public IP addresses and, like all Linux systems, have default superuser accounts like root that must be locked down. IT managers need an automated solution for taking control of these systems, one that enables them to dynamically provision accounts, set up role-based access and privilege controls, enforce consistent policies and audit activity on these new systems.

The Centrify Solution

Centrify's "enterprise-out" approach establishes Active Directory as the center of trust between enterprise and cloud servers, whether private or hosted, to make them as secure and compliant with regulations as those in your data center. Centrify DirectControl will auto-join cloud VMs to Active Directory upon first boot when deployed within VMware vApp templates or Amazon AMI images. DirectControl and DirectAuthorize ensure that superuser accounts are locked down, accounts and privileges are automatically provisioned, and consistent security policies are enforced. Centrify DirectSecure provides the unique capability to isolate specific groups of trusted systems so that they can communicate only with each other regardless of location, and to optionally encrypt data in motion between them. Centrify also provides unique visibility into your cloud environment through Centrify DirectManage Deployment Manager, which auto-discovers and manages VMware vCloud servers and Amazon EC2 instances.

Once systems are deployed, Centrify DirectAudit can verify that privileged access controls are in place and working as expected. Enterprise single sign-on not only to systems but to SAP and web application can be implemented.

The result is a dynamically updating, hardened cloud infrastructure that is secure from inside your enterprise, out through the public network, and into your private or hosted cloud environment.

Also see our Virtualization Security & Auditing solution to see how Centrify addresses security and management issues as systems move from physical to virtual.

Learn More

Next Steps