Cross-tenant access focus
In a cloud computing environment, a cross-tenant access security measure monitors conditional access policies for changes or additions that hamper or threaten an authorized access from an assistant tenant user to a focus tenant. Some cross-tenant access security tracks role assignments to detect rogue roles, or detect hampering role changes. In some cases, focus tenant events and assistant tenant events are correlated in an audit. In some cases, the authorized access is a zero standing time bound access. In some cases, the authorized access is constrained to an IP address range, or constrained to login from a managed device, or both. In some cases, assets are excluded from managed response remediation actions. In some, managed response is modulated by product-specific Role Based Access Control. In some, repeated logins are avoided, to permit faster managed responses.
1 . A cybersecurity method for focused secure cross-tenant access, the method comprising computationally, by a processor:
granting a first tenant permission to perform at least one remediation action on one or more second assets of a second tenant;
identifying an attempted cross-tenant access from the first tenant to a particular second asset of the second tenant, the attempted cross-tenant access requesting to perform a particular remediation action relating to the particular second asset; and
computationally restricting the attempted cross-tenant access based on at least an exclusion group including the particular second asset,
wherein the exclusion group specifies that the particular second asset is excluded, as opposed to included, based on at least one of: a membership in the exclusion group, an exclusion flag, an exclusion property, or an exclusion tag which is stored in the particular second asset or stored in association with the particular second asset.
2 . The method of claim 1 , further comprising:
computationally creating the exclusion group.
3 . The method of claim 1 , further comprising:
computationally creating a product-specific cross-tenant role for the first tenant.
4 . The method of claim 3 , wherein computationally creating the product-specific cross-tenant role comprises at least one of:
utilizing an access-on-behalf-of service; or
utilizing a workload cross-tenant role management service.
5 . The method of claim 3 , further comprising:
granting, to the first tenant, built-in access to the particular second asset in the second tenant after authorization in the product-specific cross-tenant role.
6 . The method of claim 1 , further comprising:
receiving a granular delegated admin privileges token from an identity provider; and at least one of:
using the granular delegated admin privileges token to query a device API; or
using the granular delegated admin privileges token to query an identity API.
7 . The method of claim 1 , wherein the first tenant is provided with access to perform remediation actions on one or more second devices of the second tenant and restricted from performing remediation actions on one or more other second devices of the second tenant that are in the exclusion group.
8 . The method of claim 1 , wherein the first tenant is provided with access to perform remediation actions for one or more second users of the second tenant and restricted from performing remediation actions for one or more other second users of the second tenant that are in the exclusion group.
9 . A computing system configured for focused secure cross-tenant access, the system comprising:
a digital memory;
a processor set comprising at least one processor, the processor set in operable communication with the digital memory, the processor set configured to:
grant a first tenant permission to perform at least one remediation action on one or more second assets of a second tenant;
identify an attempted cross-tenant access from the first tenant to a particular second asset of the second tenant, the attempted cross-tenant access requesting to perform a particular remediation action relating to the particular second asset; and
restrict the attempted cross-tenant access based on at least an exclusion group that includes the particular second asset;
wherein the exclusion group specifies that the particular second asset is excluded, as opposed to included, based on at least one of: a membership in the exclusion group, an exclusion flag, an exclusion property, or an exclusion tag which is stored in the particular second asset or stored in association with the particular second asset.
10 . The system of claim 9 , wherein the processor set is further configured to:
allow the first tenant to access to another second asset of the second tenant after authorization.
11 . The system of claim 9 , wherein the processor set is further configured to:
determine, based on at least the exclusion group, that the particular second asset comprises an excluded asset.
12 . The system of claim 11 , wherein the exclusion group comprises at least one of: a device group, or a user account group.
13 . The system of claim 9 , wherein the particular remediation action is performed by at least one of:
an endpoint security tool;
an identity security tool; or
an application security tool.
14 . The system of claim 9 , wherein the processor set is configured to implement a permissions calculation software component, which, upon execution, gets a cross-tenant role assignment and calculates a user permission based on at least the cross-tenant role assignment.
15 . The system of claim 9 , wherein the processor set is configured to implement a permissions calculation software component which, upon execution, gets a partner tenant group membership and calculates a user permission based on at least the partner tenant group membership.
16 . A computer-readable storage device configured with data and instructions which, upon execution by a processor, cause a computing system to perform a focused secure cross-tenant access method, the method comprising:
granting a first tenant permission to perform at least one remediation action on one or more second assets of a second tenant:
identifying an attempted cross-tenant access from the first tenant to a particular second asset of the second tenant, the attempted cross-tenant access requesting to perform a particular remediation action relating to the particular second asset; and
computationally restricting the attempted cross-tenant access based on an exclusion group including the particular second asset,
wherein the exclusion group specifies that the particular second asset is excluded, as opposed to included, based on at least one of: a membership in the exclusion group, an exclusion flag, an exclusion property, or an exclusion tag which is stored in the particular second asset or stored in association with the particular second asset.
17 . The computer-readable storage device of claim 16 , wherein the method further comprises:
granting, to the first tenant, access to another second asset that is not in the exclusion group based on an authorization of the first tenant.
18 . The computer-readable storage device of claim 16 , wherein the method further comprises:
determining a product-specific role status of another second asset based on at least a product-specific cross-tenant role.
19 . The computer-readable storage device of claim 16 , wherein the method further comprises;
receiving a granular delegated admin privileges token from an identity provider.
20 . The computer-readable storage device of claim 19 , wherein the method further comprises at least one of:
using the granular delegated admin privileges token to query a device API regarding the particular second asset; or
using the granular delegated admin privileges token to query an identity API regarding the particular second asset.