Startup DreamersStartup Dreamers
  • Home
  • Startup
  • Money & Finance
  • Starting a Business
    • Branding
    • Business Ideas
    • Business Models
    • Business Plans
    • Fundraising
  • Growing a Business
  • More
    • Innovation
    • Leadership
Trending

Science And Action Are Driving Global Ozone Recovery

September 16, 2025

How Morning Brew’s CEO Succeeds in a Noisy Media Landscape

September 16, 2025

How a Mom’s Garage Side Hustle Hit $1 Billion Revenue

September 16, 2025
Facebook Twitter Instagram
  • Newsletter
  • Submit Articles
  • Privacy
  • Advertise
  • Contact
Facebook Twitter Instagram
Startup DreamersStartup Dreamers
  • Home
  • Startup
  • Money & Finance
  • Starting a Business
    • Branding
    • Business Ideas
    • Business Models
    • Business Plans
    • Fundraising
  • Growing a Business
  • More
    • Innovation
    • Leadership
Subscribe for Alerts
Startup DreamersStartup Dreamers
Home » Managing Fine-Grained Access In Multicloud Environments
Innovation

Managing Fine-Grained Access In Multicloud Environments

adminBy adminSeptember 6, 20230 ViewsNo Comments5 Mins Read
Facebook Twitter Pinterest LinkedIn Tumblr Email

Head of Standards for Strata Identity, former Burton Group analyst and technology executive at Chase Manhattan Bank (now JPMorgan Chase).

Cloud computing has been a great enabler to enterprises, speeding up operations and allowing organizations to move up the digital maturity journey faster and more effectively. However, multiple clouds—especially when they have to intersect with on-premise systems and one another—can produce some challenges I’ve discussed before.

Many organizations can end up with an “identity gridlock” of competing identity systems and protocols since each cloud platform cannot exchange access policy data with other cloud providers. Identity orchestration offers some relief to this balkanization of access management, but in the end, an enterprise wants a unified, policy-based framework to manage access to its assets and enforce access controls.

Zero trust, least privilege and just-in-time access are all solid strategies and approaches to creating a secure environment that can be greatly enabled by a philosophy of fine-grained access control.

This idea of fine-grained access is similar to accessing an office building: Swiping an ID card at the entrance to the elevators confirms a user is authorized to enter the premises. It can give a user access to enter the building—all floors, all conference rooms and all offices, from the break room to the money vaults and server rooms. On the other hand, the card may only give employees access to those floors where they work, to their own offices or to the lab or workshop where they are authorized to be. A chemist can walk into the lab, while an entry-level office worker may only have access to the cafeteria and the cubicle pool on their floor.

In the digital world, fine-grained access limits an identity to those applications and assets the user requires for their job function. However, unlike coarse-grained control, which uses only one marker to grant or revoke access—such as the user’s job function—fine-grained authorization is ruled by multiple factors in tandem, such as the right user accessing the network from the right IP address in the right geographic location.

Fine-grained access can also adapt to conditions based on certain attributes—for example, a user logging on from outside of their usual network or IP address may be authorized to open a file on read-only mode with no permission to make edits.

Fine-Grained Access Needs Standards

This sounds like an ideal state of affairs, but it faces some hurdles—starting with the lack of interoperability. There are industry standards such as the Extensible Access Control Markup Language (XACML) (de facto) or Open Policy Agent (OPA) (de jure) as well as open-source options like the Amazon Cedar policy language that was announced in May 2023. Many proprietary models also exist, whether within cloud platforms themselves or in stand-alone authorization products.

However, large enterprises are frequently deploying applications across multiple clouds, and they’re using several incompatible identity systems. The marketplace is missing an approach that allows for policy interoperability. Standards such as SAML and OIDC have helped with federating identity and enabling single sign-on across security domains, but policy interoperability will require a new approach to address this long-standing need.

A newer initiative with the CNCF, called IDQL/Hexa, aims to function as a master key that can get users where they need to be by creating an approach whereby a common access policy can be translated into the runtime format used by standards-based, open-source or even proprietary access systems. This approach aims to eliminate the manual work and duplicated effort required to manage policies in each distinct identity system.

The Road Ahead For Standards Like IDQL/Hexa

Building and introducing a new standard in the identity or security industry follows a typical pattern where 1) the problem area is recognized, 2) a group forms to begin scoping and specifying a new approach, 3) additional groups (vendors and enterprises) join the effort, 4) the effort is taken up by a standards organization, and 5) a new standard ultimately is ratified.

There can be challenges along the way, of course, where incumbent players are satisfied with the status quo, and it can sometimes be difficult to make compromises with your real or perceived competitors. However, the industry has a pretty good track record of standards that have been published by the likes of ITEF, OASIS, OpenID Foundation and others.

Overcoming issues, challenges and disagreements during the standards-making process requires a lot of open dialog and debate. Ultimately, vendors and enterprise customers work toward building a consensus and doing what’s best for the industry.

A declarative and interoperable format that serves as a common language for implementing and orchestrating policies needs to emerge. Thanks to a number of open-source and standards-based initiatives, there are candidates to be the standard-bearer in this endeavor, which makes it an exciting time to be part of this industry-shaping effort.

Forbes Technology Council is an invitation-only community for world-class CIOs, CTOs and technology executives. Do I qualify?

Read the full article here

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Related Articles

Science And Action Are Driving Global Ozone Recovery

Innovation September 16, 2025

How Many Emmy Awards Did ‘Severance’ Win at the 2025 Emmys?

Innovation September 15, 2025

When To See A Dramatic ‘Planet Parade’ This Week As Worlds Align

Innovation September 14, 2025

UFC Cuts Ties With Hard-Luck Former TUF Finalist

Innovation September 13, 2025

We Are At Acute Agency Decay Amid AI. 4 Ways To Preserve Your Brain

Innovation September 12, 2025

49ers Brock Purdy May Miss Week 2 With Toe And Shoulder Injuries

Innovation September 11, 2025
Add A Comment

Leave A Reply Cancel Reply

Editors Picks

Science And Action Are Driving Global Ozone Recovery

September 16, 2025

How Morning Brew’s CEO Succeeds in a Noisy Media Landscape

September 16, 2025

How a Mom’s Garage Side Hustle Hit $1 Billion Revenue

September 16, 2025

OpenAI Ramps Up Robotics Work in Race Toward AGI

September 16, 2025

How Many Emmy Awards Did ‘Severance’ Win at the 2025 Emmys?

September 15, 2025

Latest Posts

How to Build a Business That Thrives in Tough Economic Times

September 15, 2025

Why College No Longer Has a Monopoly on Success

September 15, 2025

When To See A Dramatic ‘Planet Parade’ This Week As Worlds Align

September 14, 2025

Want to Retire One Day? Avoid 3 Common Retirement Mistakes

September 14, 2025

Why Steve Aoki is Backing Brain-Boosting Gum Brand

September 14, 2025
Advertisement
Demo

Startup Dreamers is your one-stop website for the latest news and updates about how to start a business, follow us now to get the news that matters to you.

Facebook Twitter Instagram Pinterest YouTube
Sections
  • Growing a Business
  • Innovation
  • Leadership
  • Money & Finance
  • Starting a Business
Trending Topics
  • Branding
  • Business Ideas
  • Business Models
  • Business Plans
  • Fundraising

Subscribe to Updates

Get the latest business and startup news and updates directly to your inbox.

© 2025 Startup Dreamers. All Rights Reserved.
  • Privacy Policy
  • Terms of use
  • Press Release
  • Advertise
  • Contact

Type above and press Enter to search. Press Esc to cancel.

GET $5000 NO CREDIT