Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
PhLR
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
5 ms
·
1.
▲
by
PhLR
2y ago
100%. Instead keep track of where they sign up with their business email and explain why they can't use those tools.
2.
▲
by
PhLR
2y ago
Indeed, there are some great alternatives for discovering Shadow IT, some with more or less overhead (i.e. browser extensions that nobody wants to install).
3.
▲
by
PhLR
2y ago
Another interesting approach I learned from the Director of IT at Intercom (Emanuele Sparvoli): They pay for a single seat in each of the typical "Shadow IT" SaaS apps. Then they block within the SaaS app the ability to sign up wi
4.
▲
by
PhLR
2y ago
The biggest challenge is that there's an abundance of SaaS tools that are free to use or have extensive free trials. This often lures employee's in "just trying" a platform and ending up importing critical company data.
5.
▲
by
PhLR
2y ago
We talked to lots of CISOs, InfoSec managers and IT admins about that issue. There's basically two camps: Actively block any new tool vs. not block but educate so people don't do anything stupid. I feel not blocking makes most sen
6.
▲
by
PhLR
2y ago
Indeed, when I learned about it I felt stupid for not having somebody run a regular report. Everybody talks about Shadow IT but most companies have a decent option to uncover a large chunk of it quite easily
7.
▲
by
PhLR
2y ago
Good eye, but no, not related at all
8.
▲
by
PhLR
2y ago
Thanks!
9.
▲
by
PhLR
2y ago
Thanks! Any interesting findings?
10.
▲
by
PhLR
2y ago
Looks like a candidate for https://ssotax.org/friends-of-sso.html
11.
▲
by
PhLR
2y ago
Sounds like Tailscale is now a candidate for the "Friends of SSO" list https://ssotax.org/friends-of-sso.html Respect for pushing that through the org!
12.
▲
The True Cost of Okta – SSO Tax Impact
(accessowl.io)
5 points
by
PhLR
3y ago
|
0 comments
13.
▲
Stop Silly Security Awards
(sillysecurityawards.com)
3 points
by
PhLR
3y ago
|
0 comments
14.
▲
by
PhLR
3y ago
When talking about controls are you referring to provisioning? What are some examples for missing controls?
15.
▲
by
PhLR
3y ago
Do you have some examples on what granular controls are provided with Okta but missing with Google?
16.
▲
by
PhLR
3y ago
Great approach. Wish there would be more vendors like that. This way we wouldn't even need to talk about SSO-Tax, availability of SCIM/SAML etc.
17.
▲
by
PhLR
3y ago
Thanks! Happy to chat if you want to share some of the ideas you had
18.
▲
by
PhLR
3y ago
'Auditing user accounts in SaaS applications' is a pretty good summary of what the current version is about. The 'SSO-Tax' has become a synonym for the extra charges of SaaS vendors in which they usually bundle 3rd party
19.
▲
by
PhLR
3y ago
Great to see that we were not alone with the struggles! Let me know if you are up for a quick chat. Would love to learn more about your situation and how OpenOwl could help fix it. If you are up for it, my contact is in the bio
20.
▲
by
PhLR
3y ago
That's the spirit! Thanks for the kind words. Indeed, ease of use is incredibly important. After all this is a tool that needs to be used non-developer IT admins as well.
21.
▲
by
PhLR
3y ago
In future versions it will be possible to do the same with, for example, your Google SSO sign-in and 2FA enabled. The reason for the limitation is that we simply wanted to get it out into the world and see if anybody is as excited about it