Navigation

Get in touch
Logo
News

Identities & access

One account. Too many access rights?

Employees should sign in with access that matches their role and should not keep unnecessary rights when their role changes. We connect enterprise systems to your identity management, set up single sign-on and automate the lifecycle of accounts and access rights.

person using macbook pro on white table — illustrative image
Permission concept with segregation of duties · Planning and implementation by OTOKO®

Your brief for OTOKO®

What we take care of for you.

Single sign-on answers who is signing in. What that person is allowed to do in an ERP or CRM must additionally be governed by the respective permission model. We record roles, privileged activities and necessary segregation of duties. Supported applications are connected through SAML or OpenID Connect. Multi-factor methods and access conditions are set according to protection needs. Existing local emergency accounts need to be handled in a documented, controlled way.

The possible scope of services

  • Permission concept with roles per system and segregation of duties
  • Single sign-on via SAML and OpenID Connect for ERP, CRM, intranet and workflows
  • Multi-factor authentication with FIDO2 and conditional access
  • Automated user management via SCIM from the HR system
  • Recertification of permissions and logging for audits

We define the specific scope, your involvement and the acceptance criteria before the start.

Technology explained clearly

How we carry out the task.

01

Handle onboarding, role changes and offboarding reliably

The system of record for HR data supplies events for account creation, role changes and offboarding. Provisioning can use SCIM or supported connectors; not every target system supports the same functions. We test deactivation, group changes and the handling of existing sessions. When transfers fail, discrepancies must become visible. Regular reviews confirm which rights are still needed, instead of letting group memberships accumulate indefinitely.

02

Check lockout scenarios and residual access

Acceptance testing includes positive and negative access tests with different roles. We also test an outage of the identity service and the agreed emergency access. The documentation defines who is responsible for business approvals and technical administration. An application list, existing roles and typical onboarding, role change and offboarding cases are helpful.

Meeting room at the OTOKO® Cologne office

A verifiable result

What you keep working with.

  1. Permission concept with segregation of duties
  2. Connected systems with SSO and MFA
  3. Recertification process with audit log

The handover brings together implementation and documentation. Together, we review the agreed cases and record any remaining tasks.

Before the first step

Your questions about Identities & access.

Does SSO automatically prevent excessive rights?

No. Central sign-in simplifies identity, but it does not replace checking permissions in the target systems.

Can offboarding end all sessions immediately?

That depends on session management and the integration options of the applications. We check these limits and document remaining time windows and measures.

Your project

Which task would you like to solve?

Describe your situation and the desired result. The selected service will be included in the contact request.

Request this service

Our Partners

  • Microsoft
  • Microsoft Azure
  • Amazon AWS
  • Google Cloud
  • Thales Group
  • Arrow ECS
  • Vodafone
  • IBM
  • Veeam
  • Atlassian
  • JetBrains
  • NinjaOne
  • OPSWAT
  • Utimaco
  • Eviden

Accessibility

Adjust the display to suit your needs.

A simple version is not available for this page yet.

Settings currently apply to this visit. Allow saving in Cookie settings to remember them.