My main use case for Safeguard by One Identity involves the management of domain privileged accounts, therefore integrations with Active Directory, specifically for applying these to Windows and Linux servers, where RDP and SSH sessions are monitored, along with password management via the SPP module of Safeguard. Recordings are carried out through SPS, and so far it has never happened that we had to implement restrictive policies that customized the standard connection policy.
In addition, we have also implemented SPS with the SIEM for sending reports and monitoring functionalities, as well as security alerts and notifications. We have also implemented access via OAuth 2.0 for SPP access and, on some occasions, have implemented web applications through the insertion of an RDP application on a server.
A specific example of a project where Safeguard by One Identity played a central role is when there was no management of privileged accounts and access occurred without monitoring, resulting in direct access to critical systems. The customer requested the implementation of Safeguard by One Identity to resolve this situation, so we implemented both modules, SPP and SPS, importing the entire pool of privileged accounts needing maintenance, which included password management.
We also included all the most critical targets requiring SPS to record all activities performed on the machine. We added all the users needing access to these targets with these accounts and configured the various entitlements, allowing for much cleaner and more controlled governance of privileged accounts.
So far, all cases have been fairly simple and have been fully covered. There was one instance where a customer needed to integrate the SIEM not via the standard connection provided by One Identity but requested integration via APIs, which are not yet currently available. On the other hand, we encountered some critical situations regarding web applications, which were handled by customizing the script using AutoIt. It would be beneficial if One Identity implemented web application management more similarly to how CyberArk does.
View full review »