The successor to AWS Single Sign On, AWS IAM Identity Center is used to centrally manage workforce access to multiple AWS accounts and applications. It helps users to securely create or connect workforce identities and manage their access centrally across AWS accounts and applications. AWS states that IAM Identity Center is the recommended approach for workforce authentication and authorization on AWS for organizations of any size and type.
N/A
Symantec VIP
Score 10.0 out of 10
N/A
Symantec Validation and ID Protection Service (VIP) is presented as a
user-friendly, cloud-based strong authentication
service that enables enterprises to secure access to networks
and applications without impacting productivity. Also included with VIP Enterprise two-factor authentication is Symantec VIP Access Manager, a single access point to protect cloud and on-premise web apps via Single Sign-On (SSO).
IAM plays a pivotal role in our organization, addressing the unique needs of our diverse workforce, which includes full-time employees, part-timers, contractors, and client engineers who access our workloads. This multifaceted solution offers us unparalleled control over access, ensuring that each individual has precisely the permissions they need and nothing more. IAM's robust security features guarantee the protection of our valuable resources and sensitive data. As our organization expands, IAM effortlessly scales with us, adapting to changing requirements, and helping us maintain our commitment to top-tier security and efficient access management.
Symantec VIP is well suited for enterprise institutions, like our own, managing a wide range of devices and wanting to provide their users with an extra layer of security. Being able to have 2-factor authentication with a unique pin was key for us and this would be well suited for any organization that holds sensitive information like, in our case, student records. They have great support and getting issues resolved does not take much time, a quick call to support usually straightens issues out.
Make it easier for users to assume roles securely, especially in cross-account settings. This might involve simplifying the process of switching roles in the management console or creating a command for AWS CLI that supports smoother role assumption.
Policy testing tools will be invaluable for administrators when they are creating policies. If this tool is able to assess the impact of enforcing a policy it will help greatly in preventing policy misconfigurations that lead to unintended consequences.
Better user interface, AWS should simplify the IAM interface to encourage new users.
Reliability on the app. Most users dislike having the authentication app on their cell phone because if they don't have their cellular device on-hand then they're unable to authenticate.
Perhaps a bio-metric enhancement in the near future would take this application to the next level.
It gets easier with time, initially, it can be overwhelming for a fresher. Once you're used to working with roles and policies and know when and where it is required eventually it becomes easy
AWS Identity and Access Management (IAM) excels over Google Cloud IAM with its granular control, extensive service integration, and robust security features. AWS IAM provides fine-tuned access policies, versatile role delegation, and a wide array of services. Its adaptability and extensive toolset make it the preferred choice for businesses of all sizes.
Duo is good but Symantec VIP really takes the cake. Both Symantec VIP and Duo Security are used as a two factor application but Symantec VIP also allows you to use physical tokens. Some of our users prefer those over their phones and we can easily leverage Symantec VIP for that.
AWS IAM Identity Center has significantly bolstered our security posture by ensuring that only authorized personnel access our resources. This enhanced security has protected us from potential data breaches or unauthorized use of resources, mitigating risks and potential costs associated with security incidents.
While IAM brings long-term cost savings, there might be initial implementation and training costs. It's important to factor these costs into the ROI equation.
If your organization isn't used to such fine-grained access control, there might be resistance to adopting IAM. Overcoming this resistance might require additional training costs.