For the best web experience, please use IE11+, Chrome, Firefox, or Safari

LSEG improves manageability and control of their Microsoft directory environment

LSEG improves manageability and control of their Microsoft directory environment

Products

Learn how LSEG uses Active Roles to clean up their directory environment and improve AD management and administration through the use of granular delegation and group management. Through the use of Active Roles, LSEG was able to eliminate many unused privileged accounts, dramatically reducing their attack surface.

Challenges

London Stock Exchange Group (LSEG) has 60 domains across various locations, each managed through a single console. This complexity drove them to look for a solution to simplify their environment and control user accounts more effectively. Delegating privileges across their organization was challenging, particularly with so many users and locations. It became difficult to ensure every account had proper privileges.
orange bg dots

“I would recommend One Identity Active Roles based on its ability to manage domains from a single interface and provide minimal required access based on work requirements.”

Bhupesh Matwale Technical Specialist, LSEG

Solutions

"One Identity Active Roles has helped my organization reduce the number of incorrect privileged accounts through the management unit feature. It helps us identify accounts that are not in use, and while creating admin accounts, we use it to set policies regarding which required fields must be filled during account creation. This helps us keep the process clean and ensures all required attributes are filled before account creation. We have scheduled scripts on One Identity Active Roles that check if activity meets criteria. If it doesn't, it will move the account to a specified OU, disable it, or delete it, as per the defined process."

Benefits

"One Identity Active Roles helps us keep accounts consistent. For instance, when somebody leaves the company, all associated accounts get removed, which helps us eliminate unwanted accounts.

For Active Directory, the provisioning and de-provisioning capabilities work exceptionally. The de-provision feature allows account disconnection without disabling it, enabling quick reconnection with automatic group additions. This feature significantly speeds up the process compared to disabling and re-adding to groups.

The comprehensive group membership management feature is exceptional because it offers two features not available in Active Directory directly: adding multiple secondary owners and dynamic groups. The latter is only available for Azure AD, not for on-premise AD.

The best features of One Identity Active Roles include managing multiple domains from a single interface. I don't need to log into jump servers, making it very easy to log in from the web and manage it. Dynamic groups are also one of the best features, eliminating the need to add or manage members manually. The management unit is another excellent feature, which we can use as a virtual OU to identify missing elements."

The Story

LSEG uses Active Roles to view ad protect all oftheir AD domains from a single console, dramatically simplifying identity management. With Active Roles they identified and cleaned up their privileged accounts and used automation to evaluate and optimizetheir environment. Active Roles enabled LSEG to reduce their attack surface, improve identity security and streamline directory management.