Remote Access Broker With Double Approval Across Tenants
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Managing user access across different organizations in partnerships is cumbersome, often requiring manual intervention or inadequate security and control.
Innovation Solution
A remote access broker that facilitates cross-tenant vendor identity management, allowing 'double approval' for user access, sharing user lists or groups, and managing access permissions across multiple organizations without onboarding or new email registrations.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If manual intervention and configuration are used for access management, then security and control are improved, but operation complexity and time consumption increase
Solution Approach 1:
An access broker is introduced as an intermediary system between tenants and users. The broker automatically manages access permissions by receiving access requests, verifying user identities, checking tenant policies, and granting or denying access without requiring manual intervention from tenant administrators, thus maintaining security while reducing operational complexity
Solution Approach 2:
The system enables self-service access management where users can independently request access to tenants through the broker, and the broker automatically processes these requests by verifying credentials and applying security policies, eliminating the need for manual user provisioning and access configuration by tenant administrators
2Reliability
If manual configuration is used for cross-organization access, then security control is improved, but time consumption and productivity decrease
Solution Approach 1:
Tenant security policies, user credentials, and access permissions are pre-configured in the system before access requests occur. The broker uses these pre-established policies to automatically evaluate and process access requests in real-time, eliminating the need for manual security configuration during each access event and significantly reducing time consumption
Solution Approach 2:
The access broker serves as an automated intermediary that rapidly processes access requests by automatically verifying user identities against pre-configured tenant policies and making access decisions without human intervention, thus maintaining strict security control while dramatically reducing the time required for cross-organization access management
3Productivity
If automated access management is implemented, then productivity is improved, but security control and reliability worsen
Solution Approach 1:
The broker implements feedback mechanisms where access decisions are logged, monitored, and can be audited. The system continuously verifies user credentials against tenant policies and provides feedback on access request status, allowing for automatic enforcement of security rules while maintaining high productivity through streamlined automated processes
Solution Approach 2:
While maintaining automated high-speed processing, the system allows tenant administrators to self-configure security policies and access rules according to their specific security requirements. This enables automated productivity improvement while preserving security control, as each tenant can tailor the automated system to their security needs without manual intervention in each access event
Data Source
AI summary
In one embodiment, a method includes determining, by an access broker, a first group of users of a first tenant within a computer network and exposing, by the access broker, the first group of users to a second tenant within the computer network. The method may further include receiving, by the access broker, a selection of particular users from the first group of users for which the second tenant has granted remote access to one or more networked assets of the second tenant and managing, by the access broker, access of the particular users of the first tenant to the one or more networked assets of second tenant based on a group configuration for the first group of users by the first tenant and the selection of the particular users by the second tenant.


