Multi-Environment Policy Access Management
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional access management systems lack operational features for external-customer computing environments, providing limited control and visibility, and fail to account for diverse computing environments and scenarios, leading to inefficient access provisioning operations.
Innovation Solution
A multi-environment policy is introduced, configurable to define rules for provider-controlled and customer-controlled computing environments, using access vectors to manage access provisioning operations, providing managed control and visibility for integrated access management across different types of computing environments.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If conventional access management systems are used for internal resources, then access control is provided, but operational features for external-customer computing environments are lacking
Solution Approach 1:
The access management system is enhanced to provide universal access control capabilities across multiple computing environments (internal and external). The system maintains a unified policy framework that can be configured to work with different environment types, eliminating the need for separate access management systems while preserving environment-specific operational features through configurable policies
2Adaptability or versatility
If access management is provided for diverse computing environments, then comprehensive control is achieved, but system complexity increases
Solution Approach 1:
The access management system is segmented into modular components: a core policy engine that handles unified access control logic, and environment-specific configuration modules that can be selectively activated. This segmentation allows the system to support diverse computing environments without requiring all components to be active simultaneously, thereby managing complexity while maintaining versatility
3Ease of operation
If traditional access management approaches are used, then simple implementation is achieved, but control and visibility for external customers is limited
Solution Approach 1:
An intermediary access management layer is introduced between customers and computing environments. This intermediary provides enhanced control and visibility to external customers through standardized interfaces while maintaining compatibility with existing infrastructure, thereby improving customer control without proportionally increasing infrastructure complexity
Data Source
AI summary
Methods, systems, and computer storage media for providing access to computing environments based on a multi-environment policy are provided. The a multi-environment policy is configurable to define rules that have provider-controlled and customer-controlled computing environment parameters for approving access to provider-controlled computing environments and customer-controlled computing environments. In operation, a request associated a computing environment are received. The computing environment is associated with a multi-environment policy. The multi-environment policy is configurable to define the rules based on access vectors having grouped computing environment aspects for control and visibility associated with accessing computing environments. Based on the request, a determination whether the request is for a provider-controlled or a customer-controlled computing environment is made. Based on the multi-environment policy, approval-request parameters of an approval-request are communicated to receive approval-request response values. And, based on receiving the approval-request response values, a request response indicating approval or denial of the request is communicated.


