Big Data. Big Decisions
InformationWeek
Special Coverage Series


Centrify Harnesses Active Directory For Mobile Device Management

DirectControl for SaaS promises convenient single sign-on to cloud apps and services for mobile users and secure, simple deployment for IT.

Mobility can increase worker productivity -- but only if a variety of workflow and security headaches are avoided. This avoidance is easier said than done, but Centrify aims to help. Monday, the company unveiled its DirectControl for SaaS, a new service that harnesses Active Directory (AD) to allow single sign-on (SSO) access to cloud apps and services.

Created by Microsoft more than a decade ago, AD offers a central hub through which IT can manage user identities and define access to corporate data. It has become a security cornerstone not only in traditional Windows environments but also, thanks to Centrify and other third-party vendors, those that rely on UNIX, Linux and OS X. Mobility, though, presents new challenges.

More Insights

Webcasts

More >>

White Papers

More >>

Reports

More >>

BYOD injects heterogeneity into businesses that were once technologically uniform. It also increases the number of devices used regularly by each employee. These developments mean that IT has had to deal with provisioning and monitoring devices that aren't always designed for its existing infrastructure, and over whose back ends it does not have complete control. For employees, meanwhile, the changes have meant additional authentication and security hoops to jump through, each of which is a potential drain on productivity and a possible threat to corporate compliance efforts.

The rise of software-as-a-service (SaaS) and cloud computing has been a particular stimulant for this challenge; access to traditional apps that ran natively on PCs could be easily negotiated using AD, but SaaS has often demanded that users maintain a separate user name and password for each service.

[ Learn more about how to keep BYOD risks in check. See Why Mobile Device Management Isn't Enough. ]

Centrify DirectControl for SaaS enables IT to bring these disparate devices and services back under centralized management, regardless of whether or not the devices are on the corporate network. As a cloud-based service, it does not require additional appliances or changes to the firewall, meaning that existing AD infrastructure, processes and skills can be applied not only to PCs but to a variety of smartphones and tablets.

In an interview, Centrify CEO Tom Kemp said this amounts to "an easy button" for IT. Without AD, he said, administrators might have to individually shut down access to dozens of applications when an employee leaves the company. DirectControl reduces this process to a single management console, regardless of what device was used.

For users, meanwhile, the AD integration means a single username and password can cover a range of apps. SaaS tools are accessed through MyApps, a browser-based launch page that can hook into hundreds of services, including Box, Salesforce, Microsoft Office 365, WebEx and Google Apps.

MyApps is part of a larger MyCentrify portal that also offers a number of self-service utilities through which devices can be remotely wiped or locked, passcodes can be reset and account activity can be monitored. This user autonomy allows lost or stolen devices to be addressed immediately, with no delay required to accommodate IT intervention; data is thus less likely to be compromised because the window of vulnerability can be reduced. The self-service functions also diminish IT burden in general, as users can handle many common tasks themselves. Liberated from the burden of day-to-day maintenance, administrators can pursue projects that are typically forced to the backburner.

Mobile users can also opt for "zero" sign-on. This feature recognizes that authenticating individual apps on a smartphone is particularly slow and inconvenient: because handsets are better suited to consumption than to data input, the tedious task of typing user credentials can be a legitimate impediment to productivity. DirectControl for SaaS avoids this aggravation by authenticating app access as soon as a device has been unlocked, without additional passcodes.

Several other BYOD security players offer or intend to offer SSO capabilities. For example, MobileIron recently integrated the feature into its product suite, and Dell plans to include Active Directory support in an upcoming Cloud Client Manager update.

Kemp said Centrify's offering is different because its built-in access to hundreds of SaaS apps facilitates a more seamless and secure deployment. Centrify's single and zero sign-on capabilities also can also extend to native rich media apps through a developer's SDK, further stretching its reach.

Centrify also manages aspects of security differently than some of its competitors. On the one hand, its identity-centric approach to protecting data eschews sandboxing, app wrappers and other tactics that some companies use to partition corporate content from personal content. On the other hand, Centrify's service confines user identity information to the existing AD infrastructure, keeping it under IT control. DirectControl for SaaS uses Centrify's Cloud Service to communicate between an on-premises AD and the user portal, but directory content is never replicated. For businesses leery of storing sensitive user data in the cloud, this distinction could be meaningful.

Perry Carpenter, a research VP at Gartner, said in an email that his "initial thoughts about this announcement are very positive." The new offering, he wrote, "addresses a very real customer need -- gaining greater control over SaaS -- while also offering proven strategies to simplify enterprise IT burdens."

Gregg Kriezman, also a Gartner research VP, expressed similar sentiments. "The new products give an AD-centric shop a way to do [mobile device management] fundamentals," he stated in an email, "but they also have the authentication and SSO pieces." On the topic of competing programs, he wrote that, "I think Centrify has pieces, and if you look at any one piece, you will find vendors that do that piece as well or better." He countered, however, that when all the components are strung together, "you have something that's pretty nice."



Related Reading




Currently we allow the following HTML tags in comments:

Single tags

These tags can be used alone and don't need an ending tag.

<br> Defines a single line break

<hr> Defines a horizontal line

Matching tags

These require an ending tag - e.g. <i>italic text</i>

<a> Defines an anchor

<b> Defines bold text

<big> Defines big text

<blockquote> Defines a long quotation

<caption> Defines a table caption

<cite> Defines a citation

<code> Defines computer code text

<em> Defines emphasized text

<fieldset> Defines a border around elements in a form

<h1> This is heading 1

<h2> This is heading 2

<h3> This is heading 3

<h4> This is heading 4

<h5> This is heading 5

<h6> This is heading 6

<i> Defines italic text

<p> Defines a paragraph

<pre> Defines preformatted text

<q> Defines a short quotation

<samp> Defines sample computer code text

<small> Defines small text

<span> Defines a section in a document

<s> Defines strikethrough text

<strike> Defines strikethrough text

<strong> Defines strong text

<sub> Defines subscripted text

<sup> Defines superscripted text

<u> Defines underlined text

BYTE encourages readers to engage in spirited, healthy debate, including taking us to task. However, BYTE moderates all comments posted to our site, and reserves the right to modify or remove any content that it determines to be derogatory, offensive, inflammatory, vulgar, irrelevant/off-topic, racist or obvious marketing/SPAM. BYTE further reserves the right to disable the profile of any commenter participating in said activities.

Disqus Tips To upload an avatar photo, first complete your Disqus profile. | View the list of supported HTML tags you can use to style comments. | Please read our commenting policy.

Follow InformationWeek

By The Numbers

What Are Your Primary Concerns About Using Big Data Software?

Base: 417 respondents at organizations using or planning to deploy data analytics, BI or statistical analysis software
Data: InformationWeek 2013 Analytics, Business Intelligence and Information Management Survey of 541 business technology professionals, October 2012

What Do You Think?

What's your attitude about SQL analysis on top of Hadoop?
We want fast, standard SQL analysis capabilities on Hadoop ASAP
Hadoop is for unstructured data; SQL is for relational databases
We'll give SQL on Hadoop a try, but relational DBs will remain the mainstay
Given strong SQL support on Hadoop, we'd nix the data warehouse
We're not interested in Hadoop
No opinion



Related Content

From Our Sponsor

Five Big Data Challenges and How to Overcome Them with Visual Analytics

Five Big Data Challenges and How to Overcome Them with Visual Analytics

Business leaders often need a visual snapshot of data to quickly grasp and use it. This paper identifies five challenges in presenting data and how visual analytics can resolve them. Solutions are suggested to overcome the challenges of: speed, data clarity, data quality, displaying meaningful results, and dealing with outliers.

Game-Changing Analytics: How IT Executives Can Use Analytics to Create Innovation and Business Success

Game-Changing Analytics: How IT Executives Can Use Analytics to Create Innovation and Business Success

Today's competitive advantage requires a deeper understanding of your business, your market and your customers. As an IT executive, you can drive that knowledge transformation. In this white paper, learn how to make decisions as a strategic business leader and three steps to begin an analytics initiative within your enterprise.

Data Visualization Techniques: From Basics to Big Data with SAS Visual Analytics

Data Visualization Techniques: From Basics to Big Data with SAS Visual Analytics

High-performance data visualization turns sophisticated analyses into meaningful graphics, leading to faster and smarter decision making. In this white paper, learn how visual analytics can transform big data, with additional features such as real-time functionality, mobile compatibility, robust applications for technical groups and accessibility for nontechnical users.

Big Data: Lessons from the Leaders

Big Data: Lessons from the Leaders

Financial performance, competitive advantage, operational efficiency, strategic decision making - every business goal can extract value from big data, and the time for doubt or inaction has long passed. In this Economist Intelligence Unit report, in-depth interviews with data pioneers reveal the link between the effective use of big data and the bottom line among other results.

Decision-Driven Data Management: A Strategy for Better Decisions with Better Data

Decision-Driven Data Management: A Strategy for Better Decisions with Better Data

Which came first, the data or the decision? This white paper makes the case for having a decision in mind, then tailoring big data's volume, variety and velocity to achieve business results such as overcoming customer dissatisfaction or creating well-informed strategies in real time.

Informationweek Reports

Research: The Big Data Management Challenge

Research: The Big Data Management Challenge

The challenge of big data is real, but most organizations don't differentiate 'big data' from traditional data, and nearly 90% of respondents to our survey use conventional databases as the primary means of handling data. We'll help you understand what constitutes big data (it's not just size) and the numerous management challenges it poses.