Multi-Identity App Policy Enforcement via Dynamic Segmentation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

IT administrators face challenges in applying targeted administrative policies to devices and applications, particularly when multiple identities are used, leading to reduced functionality for all identities and user confusion due to the inability to differentiate policies across different user accounts.

Innovation Solution

A method and system that allow IT administrators to control application behavior by identifying active user accounts and applying specific policies to managed identities, enabling targeted policy enforcement for each identity while preserving functionality for unmanaged identities, using a client component to interpret and enforce policies within the application.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If IT administrators apply administrative policy to all identities in an application, then corporate security and management control are improved, but functionality for personal and other identities is reduced or removed

Engineering Contradiction:
Improvecorporate security controlVSAvoidapplication functionality for multiple identities
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent segments policy application by identity type, creating separate policy sets for managed identities versus unmanaged identities. The system divides the user base into distinct groups (corporate, personal, other) and applies appropriate policies to each segment, allowing corporate security requirements to be met without restricting functionality for non-corporate users.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements local quality by applying different policy characteristics to different identity segments within the same application. Managed identities receive restrictive corporate policies while unmanaged identities receive permissive policies, allowing each identity type to have optimized functionality appropriate to its purpose.

Inventive Principle:
Principle #3Local quality

2Measurement precision

If IT administrators deploy multiple copies of the same application to apply different policies, then policy targeting accuracy is improved, but device complexity and user confusion increase

Engineering Contradiction:
Improvepolicy targeting accuracyVSAvoidnumber of application copies
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent makes a single application universal by enabling it to serve multiple identity types simultaneously with different policy configurations. The application can function as both a corporate-managed application and a personal application within the same installation, eliminating the need for multiple separate application copies while maintaining precise policy targeting.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If IT administrators restrict an application to corporate access only, then corporate policy enforcement is improved, but user confusion increases due to inability to access personal functionality

Engineering Contradiction:
Improvecorporate policy enforcementVSAvoiduser accessibility
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent implements dynamic policy application where the effective policy configuration changes based on which identity is currently active in the application. When a managed identity is active, corporate policies are enforced; when an unmanaged identity is active, permissive policies apply. This dynamic switching allows the same application to provide both secure corporate access and convenient personal access without user confusion.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS9935978B2Policy application for multi-identity apps
Publication Date: 2018.04.03 MICROSOFT TECHNOLOGY LICENSING LLC
  • US9935978B2 patent drawing
  • US9935978B2 patent drawing
  • US9935978B2 patent drawing

AI summary

Controlling application behavior in the context of managed accounts. A device includes one or more applications. At least one of the applications is configured to be used with a plurality of user accounts including zero or more managed user accounts. The device includes or communicates with a client component. The client component is configured to identify active user accounts for the applications. The client component is further configured to receive policy from a management system, where the policy specifies application controls a user account basis. The client component is further configured to enforce application configuration based on the policy from the management system and the active user accounts.