Non-Provisioned Application Access Detection via Entity Consolidation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Organizations face challenges in monitoring and identifying non-provisioned usage of applications within their IT infrastructure, which can compromise security and regulatory compliance.
Innovation Solution
A method that collects data on software applications used by organizational identities, performs entity and application consolidation processes to identify main active directory accounts and generic application identifiers, and determines whether access is provisioned or non-provisioned, preventing access if accounts are deleted or inactive.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If organizations implement comprehensive monitoring of all entity activities to ensure provisioned access, then security and compliance are improved, but system complexity and monitoring overhead increase
Solution Approach 1:
The patent introduces an intermediary system that acts as a mediator between Identity Providers and applications. This intermediary consolidates entity information and maintains application definitions, enabling automated detection of non-provisioned access without requiring complex monitoring infrastructure across the entire organization. The intermediary translates and correlates data from multiple sources to identify unauthorized access patterns.
Solution Approach 2:
The system implements feedback mechanisms where the monitoring system continuously compares actual access patterns against defined application permissions. When non-provisioned access is detected, the system provides feedback by identifying and reporting these anomalies, enabling organizations to take corrective action while maintaining simplified monitoring architecture through automated detection loops.
2Reliability
If organizations require all employees to use provisioned access methods through Identity Providers, then security and monitoring are improved, but ease of access and user convenience deteriorate
Solution Approach 1:
The system performs preliminary actions by pre-defining application permissions and consolidating entity information before access attempts occur. Application definitions are established in advance that specify which entities are authorized to access which applications. This pre-configuration enables automated enforcement of provisioned access requirements without adding friction to the user experience, as the system proactively identifies and blocks non-provisioned access attempts.
3Productivity
If organizations implement automated detection systems for non-provisioned access, then compliance monitoring is improved, but false positives and detection errors may increase
Solution Approach 1:
The patent segments the detection process into distinct functional components: entity consolidation, application definition management, and access pattern analysis. By dividing the monitoring system into these specialized segments, each component can focus on its specific task with high precision. The entity consolidation segment maintains accurate entity information, the application definition segment manages permission rules, and the analysis segment detects anomalies, reducing false positives through specialized processing.
Data Source
AI summary
A method for identifying non-provisioned access to software applications, the method comprising collecting from resources used by an organization a data record of software applications used by entities of the organization and a list of accounts registered in the software applications, performing an entity consolidation process to identify a main AD account associated with a specific account, where the main AD account is the account used for provisioned access to the software applications, extracting a list of application definitions that the main AD account of the specific account is assigned to access in a provisioned manner, performing an application consolidation process to identify a generic application identifier associated with a specific application of the software applications, and determining whether the specific account accesses the specific application in a provisioned manner or a non-provisioned manner according to the application definitions of the main AD account associated with the specific account.


