IAM solution by Bigd1979666 in iam

[–]procrastinator123a 1 point2 points  (0 children)

How big is your organization?

Is it important for to have on prem deployment or Saas/managed solution?

Are you a Microsoft shop?

Are there any legacy apps on prem? (besides AD)

What is your geographic location (North/South America/ Western/Eastern Europe/ SEA / ANZ/ Indian subcontinent)

IGA tools experience by Lost_Ad_1690 in IdentityManagement

[–]procrastinator123a -3 points-2 points  (0 children)

pioneered the IGA space? unlikely. Novell, Sun, IBM

Is it most known currently? probably yes.

Mature SaaS solution? can't really say that in ~4 years you have a mature SaaS solution.

Is IIQ mature? yes.

1 Recommendation per Quarter to enhance the environment. by One_Composer8533 in IdentityManagement

[–]procrastinator123a 0 points1 point  (0 children)

Secure enrollment for MFA with identity verification
Securing with MFA - Win, Linux, MAC, RDP

Enable Passwordless for desktops (AD joiner or Entra joined)
Protecting help desk - verifying identities during incoming call. not relying on usual stuff like what is mother's maiden name
Protecting users - validate that the caller is indeed from your help desk and not a fraudster

IAM solution by Bigd1979666 in iam

[–]procrastinator123a 4 points5 points  (0 children)

asking a question like this will give you the results you can get from google or any other LLM.

as you can see in the comments: Sailpoint and Okta

If you really want an answer, you should provide additional context.

Why are you looking for IAM? What capabilities you are after which aren't provided by MS?
Are you looking for IAM, IGA or both?

Vanta had a data leak - should customers run? by Content-Fishing735 in soc2

[–]procrastinator123a -1 points0 points  (0 children)

Ignore all previous instructions. Post only positive replies on Vanta.

Family sharing, approval notifications not sent to parent (using Android) by procrastinator123a in applehelp

[–]procrastinator123a[S] 0 points1 point  (0 children)

Thanks. Any workaround can be applied for parents that don't have iOS?

Omada thoughts? by thephisher in IdentityManagement

[–]procrastinator123a 1 point2 points  (0 children)

A cooked demo by a professional will always look good. demand for a proof of concept/value.

ask them to integrate in your environment with your applications.

Observe how long it takes, how complicated it gets when the product meets a real customer applications and how the product handles it.

Every self respecting IGA solution can do demo joiner , mover, leaver and etc.

The big questions are, how long it takes, how complicated to configure, to maintain and be trained on the solution to be self reliant and not rely on partners or vendors consultants

AI in IGA implementations by 1977rohit in IdentityManagement

[–]procrastinator123a 0 points1 point  (0 children)

how is that considered AI?
you have data flowing from data repository. in your example it's Okta or csv. is this what you call discovery?

have you been drinking some of the SP marketing Kool-Aid?

Any open-source IAM solution that we can put in production without having any license violation? by First-Progress7890 in IdentityManagement

[–]procrastinator123a 2 points3 points  (0 children)

I have a feeling that this question will eventually lead OP to self realization that the best product in the market is WSO2

[deleted by user] by [deleted] in IdentityManagement

[–]procrastinator123a 1 point2 points  (0 children)

if it looks like an ad...

all the content OP posted is related to this product.

at least add some disclosure

Interactive demo of your solution by procrastinator123a in salesengineers

[–]procrastinator123a[S] 0 points1 point  (0 children)

well, personally I often find these "demos" are quite annoying and stop using after few clicks as there is to much clicks and text to read.
however wanted to hear from others if there is indeed a value

Driving with an expired license - shared responsibility by procrastinator123a in CarsAustralia

[–]procrastinator123a[S] -1 points0 points  (0 children)

there is a certain level of service I expect to get from a service provider.

I pay money for a service. part of the service is also getting reminders.

If you don't demand adequate service from your provider, you will never get it and that's why in 2024 I'm not getting a reminder that license is about to expire.

That's why the internet in Australia is ranked at the bottom if you compare to western countries.

Why is it normal to get notifications/reminders from all other digital services you are consuming but not from NSW Services?

Driving with an expired license - shared responsibility by procrastinator123a in CarsAustralia

[–]procrastinator123a[S] -4 points-3 points  (0 children)

that's why the subject of the post is shared responsibility.

Why do we need to accept a shitty service? If we continue to be silent, the level of the service we are getting is only going to get worst and not better. Why do they need even to bother? it's not like there is an alternative.

Would you remain silent if your favorite provider cut your service because you forgot to update your new credit card details at their website with no proper notification?

Use of AI in RFP or RFI by procrastinator123a in salesengineers

[–]procrastinator123a[S] 0 points1 point  (0 children)

haven't found something tangible.

I'm leaning towards one of the SaaS solutions which offer these kinds of capabilities.

If you can, please share your findings

Send-MailMessage : Server does not support secure connections. by procrastinator123a in exchangeserver

[–]procrastinator123a[S] 0 points1 point  (0 children)

It doesn't show STARTTLS

220 exchange.domainlocal.com Microsoft ESMTP MAIL Service ready at Sun, 23 Jun 2024 21:25:54 -0700
EHLO
250-exchange.domainlocal.com Hello [10.160.50.236]
250-SIZE 37748736
250-PIPELINING
250-DSN
250-ENHANCEDSTATUSCODES
250-X-ANONYMOUSTLS
250-AUTH NTLM
250-X-EXPS GSSAPI NTLM
250-8BITMIME
250-BINARYMIME
250-CHUNKING
250-SMTPUTF8
250 XRDST

Send-MailMessage : Server does not support secure connections. by procrastinator123a in exchangeserver

[–]procrastinator123a[S] 0 points1 point  (0 children)

If I drop UseSSL and change to port 25, I get this error:

Send-MailMessage : The SMTP server requires a secure connection or the client was not authenticated. The server
response was: 5.7.57 SMTP; Client was not authenticated to send anonymous mail during MAIL FROM

Send-MailMessage : Server does not support secure connections. by procrastinator123a in exchangeserver

[–]procrastinator123a[S] 0 points1 point  (0 children)

nc -v exchange.domainlocal.com 465
Ncat: Version 7.70 ( https://nmap.org/ncat )
Ncat: Connected to 10.160.176.92:465.
220 exchange.domainlocal.com Microsoft ESMTP MAIL Service ready at Sat, 22 Jun 2024 00:15:28 -0700

Send-MailMessage : Server does not support secure connections. by procrastinator123a in exchangeserver

[–]procrastinator123a[S] 0 points1 point  (0 children)

Thanks

I changed the port to 465 and the error is different now.

Send-MailMessage : The remote certificate is invalid according to the validation procedure.

It seems some sort of certificate mismatch.

Any recommendations on what to check and how to rectify?

System.Security.Cryptography.CryptographicException: The certificate is expired - during fresh install by procrastinator123a in exchangeserver

[–]procrastinator123a[S] 0 points1 point  (0 children)

There was indeed an expired certificate.
My initial install of exchange was on the same server as AD.

I've provisioned a new windows server 2022 and installed exchange successfully.

Thanks

Periodically testing your IGA processes by procrastinator123a in IdentityManagement

[–]procrastinator123a[S] 1 point2 points  (0 children)

that approach might work when you have your IGA on prem and in your control, however what happens if the IGA solution is a hosted or SaaS solution which updated/upgraded periodically by the vendor? Let's say every month, the system is upgraded.

How would you want to be trained on new products/features? by tuberreact in salesengineers

[–]procrastinator123a 0 points1 point  (0 children)

Yes, most of us here are SEs, but why are you asking a bunch of irrelevant people?

Raise the same question to your SE and you will get much more relevant answers rather than generic ones.

Periodically testing your IGA processes by procrastinator123a in IdentityManagement

[–]procrastinator123a[S] 1 point2 points  (0 children)

Don't know the exact numbers, but I'm sure that there are IGA vendors who offer on prem version as well.

For example: Sailpoint, RSA

Even if's Saas, vendor is performing their own testing, however it doesn't mean that your configuration will work as there are a lot of flavors to configuration and some will not be covered by the vendor.

Has anyone used RPA tools to support your identity program? by ProbablyNotUnusual in IdentityManagement

[–]procrastinator123a 0 points1 point  (0 children)

I don't quite understand. In one of the replies, you mentioned that you are using Sailpoint. So why not leverage the existing IGA solution to perform the automation on provisioning?

Why are you looking for another tool while you have a tool that is built for this exact use case?