Skip Links

Network World

  • Social Web 
  • Email 
  • Close

BitKoo clamps tight user controls on SharePoint

Vendor integrates access controls; adds auditing, reporting, delegated administration
By John Fontana , Network World , 08/04/2008
  • Share/Email
  • Comment
  • Print

Access-control vendor BitKoo Monday unveiled an authentication and authorization gateway that lets users control internal and external access to Microsoft's SharePoint server

BitKoo's Keystone SP also provides auditing, reporting, delegated administration and the ability to validate user access-control settings periodically. Keystone was developed inside The Walt Disney Co. as the foundation for its internal identity-management system before Bitkoo took the platform commercial.

SharePoint has become one of the fastest-growing products in Microsoft's history despite some of its limitations in securing full-scale enterprise rollouts. Those limitations include a lack of sophisticated access controls beyond SharePoint's document-specific controls, and the need for third-party add-ons to support corporatewide rollouts.

SharePoint does provide a limited number of access controls via its integration with Active Directory, but integration with third-party systems is complicated or impossible. Users also can use Keystone SP to eliminate Active Directory from the SharePoint security equation.

Keystone SP is a gateway that sits between SharePoint and any number of authentication and authorization platforms, including those based on the Lightweight Directory Access Protocol, Kerberos and RADIUS.

When SharePoint needs to talk to an authentication provider, it does so through Keystone SP, a process that lets users add or replace authentication technologies without having to modify SharePoint.

For the server to recognize Keystone SP, users have to install a Dynamic Link Library on the SharePoint site and alter one configuration field in SharePoint. Once data begins to flow through Keystone SP, users can take advantage of such features as delegated administration, segregation of duties, auditing and reporting.

"SharePoint is pretty good for departments, but for the enterprise, we add that missing link in security, audit, reporting and compliance," said Doron Grinstein, CEO of BitKoo, who wrote the Keystone code while at Disney.

To deal with users outside the firewall, Keystone SP includes BitKoo's SecureWithin technology, which allows internal resources to be exposed only to authorized clients. SecureWithin does not require a VPN, DMZ replication, or network or firewall reconfiguration to provide access to outside users securely. In addition, Keystone SP can determine a user's role in the organization and assign group permissions based on that role.

  • Share/Email
  • Comment
  • Print
Partner Content

Brilliantly simple security and control solutions for email, web and endpoint

www.sophos.com

Stopping data leakage

Learn how to exploit your current security investment to control the information that flows into, through and out of your network.

Download the white paper.

Why detection rates aren't enough

Evaluating endpoint security products is a time-consuming and daunting task. Learn the six critical questions you need to ask prospective vendors to get the right endpoint solution.

Download the white paper.

Applications: taking back control

Employees installing unauthorized applications is a growing threat to business security and productivity. Cost-effectively reduce this threat by integrating control into your malware protection.

Learn more today.

Comment
Login
Forgot your account info?
Add comment
Anonymous comments subject to approval. Register here for member benefits.
Have a NetworkWorld account? Log in here. Register now for a free account.

Videos

rssRss Feed