IP Library › Granted Patent US 12,254,107
Granted Patent B2
US 12,254,107 · App. 17/667,292 · Granted Mar 18, 2025

Orchestration of administrative unit management

Inventors: Andrey Mikhaylovich Polevoy (Khimki, RU); Robert John Bobel, III (Westerville, OH)
Assignee: CAYOSOFT, INC.
G06F21/6218G06F21/604G06F2221/2141
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,254,107
App. No.
17/667,292
Granted
Mar 18, 2025
Kind
B2
Abstract

Methods, systems, and computer program products for implementing an administrative unit management process. An object membership request that includes a membership access change for an object for one or more administrative units of a plurality of administrative units is received at a management service from a client device. Membership evaluation information associated with the object is obtained from a directory service for the plurality of administrative units. A membership change action is determined based on the membership evaluation information. Instructions are provided to at least one administrative unit of the plurality of administrative units to implement the membership change action. A membership change notification is sent to the client device.

Claims (34)

1. A computer-implemented method comprising:

at a processor of a device:

obtaining membership data for a plurality of objects associated with a plurality of administrative units, wherein the plurality of administrative units comprises a first set of administrative units that enforce mutually exclusive object memberships and a second set of administrative units that do not enforce mutually exclusive object memberships;

identifying, at a management service and based on the membership data, a membership access change for at least one object of the plurality of objects for one or more administrative units of the plurality of administrative units;

obtaining, at the management service, membership evaluation information associated with the at least one object;

determining, at the management service, a membership change action for the at least one object based on the membership evaluation information, wherein determining the membership change action for the at least one object based on the membership evaluation information is based on permission roles and assigning permission delegation to a user;

in response to determining an approved membership change action, providing instructions to at least one administrative unit of the plurality of administrative units to implement the membership change action for the at least one object of the plurality of objects; and

sending a membership change notification to a client device.

2. The method of claim 1 , wherein determining the membership change action for the at least one object based on the membership evaluation information comprises determining to delegate administrative rights to one or more objects of the plurality of objects for a particular administrative unit.

3. The method of claim 1 , wherein determining the membership change action for the at least one object based on the membership evaluation information comprises determining to remove access to one of the administrative units for the at least one object.

4. The method of claim 1 , wherein determining the membership change action for the at least one object based on the membership evaluation information comprises determining to provide access to another administrative unit for the at least one object.

5. The method of claim 1 , wherein the membership change action comprises a membership conflict between the at least one object and memberships associated with the at least one object corresponding to another administrative unit.

6. The method of claim 5 , further comprising displaying on a user interface at the client device a membership conflict resolution notification for the membership conflict.

7. The method of claim 1 , wherein in response to receiving the membership change action, the management service is configured to distribute the membership change action to each of the plurality of administrative units.

8. The method of claim 1 , wherein the membership evaluation information is obtained from a directory service, a file, or a management service configuration database.

9. The method of claim 1 , wherein the membership evaluation information is obtained during, or prior to, the evaluation of the membership change actions.

10. The method of claim 1 , further comprising:

tracking membership change results associated with the membership change action in a management configuration database.

11. The method of claim 10 , further comprising:

reversing one or more of the membership change actions to one or more object for each of the plurality of administrative units based on the tracked membership change results.

12. The method of claim 1 , wherein the at least one object comprises a user account object, a computer account object, one of a group of objects, an object container object, or a combination thereof.

13. The method of claim 1 , wherein the plurality of administrative units each comprise an administrative object that defines a set of member objects to which membership change actions are configured to be applied and/or enforced.

14. The method of claim 1 , wherein the management service is hosted by a cloud-based management server and accessed by the client device based on the client device comprising permissions to access the cloud-based management server.

15. A system comprising:

a non-transitory computer-readable storage medium; and

one or more processors coupled to the non-transitory computer-readable storage medium, wherein the non-transitory computer-readable storage medium comprises program instructions that, when executed on the one or more processors, cause the one or more processors to perform operations comprising:

obtaining membership data for a plurality of objects associated with a plurality of administrative units, wherein the plurality of administrative units comprises a first set of administrative units that enforce mutually exclusive object memberships and a second set of administrative units that do not enforce mutually exclusive object memberships;

identifying, at a management service and based on the membership data, a membership access change for at least one object of the plurality of objects for one or more administrative units of the plurality of administrative units;

obtaining, at the management service, membership evaluation information associated with the at least one object;

determining, at the management service, a membership change action based on the membership evaluation information, wherein determining the membership change action for the at least one object based on the membership evaluation information is based on permission roles and assigning permission delegation to a user;

in response to determining an approved membership change action, providing instructions to at least one administrative unit of the plurality of administrative units to implement the membership change action for the at least one object of the plurality of objects; and

sending a membership change notification to a client device.

16. The method of claim 1 , wherein, in response to determining an approved membership change action, providing instructions to a first administrative unit of the first set of administrative units and a first administrative unit of the second set of administrative units to implement the membership change action, and providing instructions to a second administrative unit of the first set of administrative units to deny the membership change action.

17. The method of claim 1 , wherein determining the membership change action for the at least one object based on the membership evaluation information comprises determining that there are mutually exclusive memberships between two or more administrative units.

Assignments (2)
SECURITY INTEREST Recorded Sep 29, 2025
From: CAYOSOFT, INC.
To: CANADIAN IMPERIAL BANK OF COMMERCE
Reel/Frame 072409/0589 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 9, 2022
From: POLEVOY, ANDREY MIKHAYLOVICH; BOBEL, ROBERT JOHN, III
To: CAYOSOFT, INC.
Reel/Frame 058934/0045 →
Continuity (2)
Provisional Application 63147433 · Feb 9, 2021
Related Publication 20220253542A1 · Aug 11, 2022
References Cited (24)
US 7350226B2 · Moriconi et al. · 2008 [cited by applicant]
US 7568217B1 · Prasad et al. · 2009 [cited by applicant]
US 9137263B2 · Chari et al. · 2015 [cited by applicant]
US 9411977B2 · Buss · 2016 [cited by applicant]
US 10554615B2 · Teverosky et al. · 2020 [cited by applicant]
US 10715514B1 · Threlkeld · 2020 [cited by applicant]
US 20060156020A1 · Minium · 2006 [cited by examiner]
US 20060294578A1 · Burke · 2006 [cited by examiner]
US 20070283443A1 · McPherson · 2007 [cited by examiner]
US 20140059651A1 · Luster et al. · 2014 [cited by applicant]
US 20140196115A1 · Pelykh · 2014 [cited by examiner]
US 20140289207A1 · Moloian · 2014 [cited by examiner]
US 20150012966A1 · Tandon · 2015 [cited by examiner]
US 20160359965A1 · Murphy et al. · 2016 [cited by applicant]
US 20190334917A1 · Demmler · 2019 [cited by examiner]
US 20200344212A1 · Devireddy et al. · 2020 [cited by applicant]
US 20210329037A1 · O'Byrne · 2021 [cited by examiner]
KR 20130077433A · 2013 [cited by applicant]
WO 2019005512A1 · 2019 [cited by applicant]
WO 2020167928 · 2020 [cited by applicant]
European Patent Office (ISA/EP), International Search Report and Written Opinion of the International Searching Authority, International Application No. PCT/US2022/015677, 12 pages, May 23, 2022. [cited by applicant]
Sandu, R.S., “Role-Based Access Control Models,” IEEE Computer Society, IEEE, USA, vol. 29, No. 2, pp. 38-47, Feb. 1996. [cited by applicant]
Roberts, T., “An introduction to Azure AD administrative units,” https://4sysops.com/archives/an-introduction-to-azure-ad-administrative-units/, 18 pages, Jan. 6, 2021. [cited by applicant]
“Synchronizing group membership,” Cloudera, Inc., https://docs.cloudera.com/management-sole/cloud/user-management/lopics/f , 2 pages, Feb. 24, 2021. [cited by applicant]