Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

How Active Roles by One Identity supports IAM in a university environment

Managing user accounts, permissions and security access across a university environment involves significant administrative work. For institutions that rely on Microsoft Active Directory, keeping that infrastructure organized, secure and current can quickly become resource-intensive as student and staff populations shift each semester. This type of challenge grows when IT teams must handle onboarding, access changes and offboarding manually for each individual.

Best practices: How to implement Kerberos authentication correctly in your AD environment

Authentication configuration issues, especially those tying into Kerberos, are a big call driver for the Active Roles by One Identity Support team. When Kerberos requirements are met, Integrated Windows Authentication typically attempts Kerberos before falling back to NTLM. Due to expected IIS functionality, we will see multiple HTTP requests which trigger authentication repeatedly.

PAM ROI: Modern privileged access management pays for itself

Privileged access management (PAM) is one of the clearest ways to reduce identity-based risk and demonstrate security value. But ROI depends on more than simply deploying a PAM tool. Organizations need a solution that can be implemented efficiently, managed without unnecessary operational burden and scaled in a way that supports long-term cost control. For organizations evaluating PAM investments, these factors matter.

'Set menu or à la carte?' Customizing the Identity Manager UI

A “set menu” or “à la carte” design? Drawing on nearly 12 years of experience using Identity Manager by One Identity, Andrew Edney, a lead consultant at iC Consult, gives a lightning-quick breakdown of useful UI customization options using Designer, including changes to overview forms and updating navigation with features like custom filtering.

How identity sprawl is quietly expanding your attack surface

No city is designed to become complex. It starts with a simple plan with a handful of streets and a few neighborhoods. Then it grows. New districts appear, roads extend, bridges get built and temporary solutions slowly become permanent. As cities grow, complexity compounds, perhaps because that growth was never planned for. Identity environments follow the same pattern.

EMEA compliance just made sovereign cloud mandatory

For years, sovereign cloud was basically a data center pin on a map. A vendor would point at Frankfurt or Paris and call it a day. That pitch doesn’t work anymore, and it stopped working fast. Between late 2024 and late 2025, the EU passed three separate rules that turned sovereignty from a talking point into something organizations now have to prove, on a schedule, with documentation, to a specific regulator.

Your AD is a stomping ground for lateral movement

Active Directory (AD) is the backbone many enterprises lean on for their IT environments. Yet, most organizations rarely govern the directory with the scrutiny necessary. This was the throughline of a recent webinar with Nitish Deshpande, senior analyst at KuppingerCole, and Robert Kraczek, global strategist at One Identity. The pair made a strong case for mediating admin access to AD, emphasizing just how easily compromised credentials can beget full-blown incidents.