About identity management

Overview

Incydr's identity management functionality is an important security feature that allows you to give users access to the right resources within Incydr. 

Incydr separates the concepts of user authentication and authorization. This approach gives you the flexibility to create and customize your environment based on your organization's needs for security, scalability, employee productivity, and user management.

This article describes the options for connecting your Incydr environment with authentication and provisioning providers for user authentication and authorization: 

  • Single sign-on (SSO)
  • SCIM provisioning
  • Incydr User Directory Sync
  • Local Incydr directory

Comparison of authentication and authorization methods

Each method of authentication and authorization has advantages for different situations. This list describes a few of the highlights of each method.

Method Capability Advantages Disadvantages Scalability
Incydr User Directory Sync  Authorization only
  • Use LDAP to connect your directory service, such as active directory (AD), to Incydr
  • User management
  • Changes made in your directory service are automatically pushed to your Incydr environment. This means security and policy changes stay in sync.
  • Requires third-party product or service
  • Existing environments must contact 

    contact your Customer Success Manager (CSM) to configure

  • Complex
High
Local Authentication and authorization
  • Default method
  • No extra setup
  • User database backed up by Incydr environment daily backup
  • No automated user management
  • Not integrated into your centralized directory service or SSO provider
  • Changes to your security or organization policies must also be applied to your Incydr environment.
  • Medium
  • Can upload multiple users in a text file
SSO Authentication only
  • Users can sign in once and access all IT services. 
  • Security benefits including reducing password fatigue for your users and limiting the number of third parties storing user credentials
  • Requires third-party product or service
High
SCIM provisioning Authorization only
  • User management
  • Changes made in your directory service are automatically pushed to your Incydr environment. This means security and policy changes stay in sync.
  • Requires third-party product or service.
High

Compatibility 

All of these methods are compatible with each other. You can choose any combination of these authentication and authorization methods. 

Authentication

Authentication is the process of identifying and verifying users. In Incydr, this occurs when:

  • Users sign in to the insider risk agent or Incydr console
  • Users are registered for the first time

Use unique usernames and passwords
Each individual user needs a unique username and password. Sharing credentials across multiple users is a large security and data privacy risk because users can download backed up files from every device using the same username. 

SSO

Implementing single sign-on (SSO) as the authentication method in your Incydr environment provides security benefits and simplifies the sign-in experience. Incydr SSO uses SAML 2.0.

Introduction and overview

Configuration instructions for Incydr cloud environments

Incydr has tested single sign-on integration with the following identity providers: 

SAML settings

You can integrate any SAML 2.0-compliant identity provider with Incydr. In some cases you may need to update the SAML configuration to work with the identity provider's settings. For directions, see Set SAML attributes for SSO.

Authorization

Authorization is the process of determining what roles and permissions a user is entitled to. Use the provisioning provider screen to configure authorization methods within Incydr.

In Incydr, authorization includes user management. User management allows Incydr to automatically activate and deactivate users, move users into organizations, and assign roles to users.

You can use any of the following authorization methods:

  • Incydr User Directory Sync
  • Local Incydr directory
  • SCIM provisioning

Incydr User Directory Sync

Using LDAP, Incydr User Directory Sync connects your directory service, such as Active Directory (AD), and your Incydr environment. 

Introduction and overview
Configuration instructions for Incydr cloud environments

SCIM provisioning

SCIM is an open standard protocol for automating user management within cloud applications. 

Introduction and overview

Configuration instructions for Incydr cloud environments

Still unsure?

Please contact sales for information on our consulting options.

Was this article helpful?
0 out of 0 found this helpful

Comments

0 comments

Please sign in to leave a comment.