Key Takeaways
- Effectual implemented an enterprise-grade Active Directory Federation Service (ADFS) for a large federal government client.
- Federated access to AWS via IAM, Active Directory, and ADFS enforces least-privilege access for client users.
- The ADFS PIV card solution enables reliable, secure connectivity for a distributed remote workforce.
- The federated approach improved credential auditing and let the client set granular permissions and access levels across systems.
- AWS CloudFormation templates standardize configuration for multi-account registration, improving efficiency and consistency over time.
Effectual led the implementation of an enterprise grade Active Directory Federation Service (ADFS) for a large Federal Government client.
Effectual enabled reliable and secure cyberspace capability by providing a highly innovative network architecture, engineering, integration, and simulation services with unrivaled expertise and commitment.
The Challenge
The client looked to our team to move its highly disparate environment into a highly collaborative one. By implementing Federated Access to the Amazon Web Services environment, this ensured least privilege access to client users.
The Solution
We worked with the client to setup an AWS Identity and Access Management (IAM), federated sign-in through Active Directory (AD), and Active Directory Federation Services (ADFS). This ensured least privilege access to client users.
The Benefits
Reliability
Our team enabled reliable collaborative connectivity to a cadre of remote workers that needed access to the system while utilizing the ADFS PIV card solution.
Increased Security
We were able to meet all security requirements by using a federated solution, allowing the client to set permissions and access levels across different systems. The Federated solution also improved auditing management of credentials.
Efficiency
We implemented AWS CloudFormation to create a template to use when multiple accounts register in the system. This led to an increase in efficiency and ensures consistent configurations overtime.
Frequently Asked Questions
What federal use case does this case study cover?
Implementation of an enterprise-grade Active Directory Federation Service (ADFS) for a large Federal Government client to enable least-privilege access to AWS.
What problem was the client trying to solve?
Moving a highly disparate environment into a collaborative one with federated access to AWS that ensures least-privilege access for client users.
How was least-privilege access achieved?
Through AWS Identity and Access Management (IAM), federated sign-in via Active Directory, and Active Directory Federation Services (ADFS).
How does the solution support remote workers?
The ADFS PIV card solution enables reliable, secure collaborative connectivity for remote workers who need system access.
What improved efficiency and consistency?
AWS CloudFormation templates standardize configuration when multiple accounts register in the system, increasing efficiency and ensuring consistent configurations over time.