Does anyone have any experience or thoughts about implementing some form of Segregation of Duties checking function within Adexes?
We are using AD group management as the primary method to control access to a number of systems/applications/functions and need to build some model that allows us to prevent certain 'toxic combinations' of access rights as defined by our compliance folk.
Whilst I could build ad-hoc checks into business rules for each group that could get rather messy and hard to maintain.
So, I was thinking about building some kind of access matrix that could then be called for a 'yes'/'no' response whenever a group addition request is processed.
So I was wondering if anyone tried this kind of thing before and might share some ideas please?
Thanks,
Bernie