niedziela, 4 listopada 2018

to use AD LDS (previously ADAM) or not?

Why to use (in 2018/2019) LDS service if we have ADFS, Active Directory and clouds? From my experience in IT:
  • it is much easier (mentally) to extend schema in dedicated directory service nor in Active Directory
  • there are many older applications or they want just use LDAP not ADFS and You want do it more secure than giving access to production directory service
  • you can have multiple instances of the same data or with different settings and scopes of attributes, for example You can give only login names and phone numbers for company A and the same data with group membership for company B without access to not needed data
  • it is very lightweight - of course - if You will create application with wrong long queries You can kill every server - I saw it at one company - they didn't use group membership info and they try to find membership by browsing groups - one by one to find in which groups user is a member of. They have 20-40k users and 25k groups so please, imagine, how can it work. After my review I pointed them, that memberof property is available in OpenLDAP, AD LDS and almost in every modern directory service.
  • it can be fully separated from main domain in scenario with publishing data in not secure environment - passwords can be sychronized as well

Brak komentarzy:

Prześlij komentarz