Enterprise user access discovery and management using policy and entitlement framework
A system and method for enabling fine-grained access to enterprise applications in an enterprise network. The method includes receiving, via a discovery application running on a computing device, user input from a user, where the user input identifies at least one of an application name, a server name, or an Internet Protocol (IP) address associated with a computing resource for accessing an enterprise application; comparing, via the discovery application, the user input to application information stored in a database accessible by the discovery application; sending, via the discovery application, a message to the user in response to determining a match between the user input and the application information, where the message identifies a membership group containing the computing resource for accessing the enterprise application; and enabling the user to access the membership group using the computing resource when the user is a member of the membership group.
1 . A method for discovering membership groups to access enterprise applications, the method comprising:
creating, via a discovery application running on a computing device, one or more entitlement rules specifying computing resources for accessing enterprise applications within a membership group;
creating, via the discovery application, one or more blocking rules corresponding to each of the one or more entitlement rules in response to creating each entitlement rule, wherein the one or more blocking rules are configured to restrict access to one or more of the enterprise applications within the membership group for a subset of one or more users in the membership group;
receiving, via the discovery application, user input from a user, wherein the user is included in the subset of one or more users in the membership group, wherein the user input identifies at least one of an application name, a server name, or an Internet Protocol (IP) address associated with a computing resource for accessing an enterprise application, and wherein the computing resource is one of the computing resources within the membership group and the enterprise application is one of the enterprise applications within the membership group;
comparing, via the discovery application, the user input to application information stored in a database accessible by the discovery application;
sending, via the discovery application, a message to the user in response to determining a match between the user input and the application information, wherein the message identifies the membership group containing the computing resource for accessing the enterprise application; and
enabling the user to access the enterprise application using the computing resource based on the one or more entitlement rules while restricting the user from accessing at least another one of the enterprise applications in the membership group based on the one or more blocking rules.
2 . The method of claim 1 , wherein the application information comprises rules for accessing computing resources in a plurality of membership groups including a first membership group.
3 . The method of claim 2 , wherein the plurality of membership groups comprises a plurality of active directory (AD) groups.
4 . The method of claim 1 , wherein before enabling the user to access the enterprise application, the method further comprises forwarding, via the discovery application, an access request from the user to an owner of the membership group.
5 . The method of claim 1 , wherein the message comprises descriptive information about the membership group.
6 . The method of claim 1 , wherein the computing resource comprises at least one of a server or a port associated with the membership group.
7 . A method for enabling fine-grained access to enterprise applications, the method comprising:
defining, via a discovery application running on a computing device, an access policy for a membership group;
creating, via the discovery application, one or more entitlement rules specifying computing resources for accessing enterprise applications within the membership group;
creating, via the discovery application, one or more blocking rules corresponding to each of the one or more entitlement rules in response to creating each entitlement rule, wherein the one or more blocking rules are configured to restrict access to one or more of the enterprise applications within the membership group for a subset of one or more users in the membership group;
receiving, via the discovery application, a request from a user to access at least one of the enterprise applications in the membership group, wherein the user is included in the subset of one or more users in the membership group; and
granting the user access to at least one of the enterprise applications in the membership group based on the one or more entitlement rules while restricting the user from accessing at least another one of the enterprise applications in the membership group based on the one or more blocking rules.
8 . The method of claim 7 , wherein the membership group comprises an active directory (AD) group.
9 . The method of claim 7 , wherein the one or more entitlement rules are defined by an owner of the enterprise applications.
10 . The method of claim 7 , further comprising storing each of the one or more blocking rules in a master block policy accessible to the discovery application.
11 . The method of claim 10 , further comprising storing the one or more entitlement rules in the master block policy.