Live data from Hacker News

Viewing profile — PhLR

PhLR

HN member
Joined
Thu, Mar 02, 2023, 4:10 PM UTC
HN karma
19
Public activity
21 items

About PhLR

Feel free to reach out: pe@accessowl.io

Recent public activity

  1. comment
    Comment #41126594

    100%. Instead keep track of where they sign up with their business email and explain why they can't use those tools.

  2. comment
    Comment #41126518

    Indeed, there are some great alternatives for discovering Shadow IT, some with more or less overhead (i.e. browser extensions that nobody wants to install).

  3. comment
    Comment #41126509

    Another interesting approach I learned from the Director of IT at Intercom (Emanuele Sparvoli): They pay for a single seat in each of the typical "Shadow IT" SaaS apps. Then they b…

  4. comment
    Comment #41126482

    The biggest challenge is that there's an abundance of SaaS tools that are free to use or have extensive free trials. This often lures employee's in "just trying" a platform and end…

  5. comment
    Comment #41126085

    We talked to lots of CISOs, InfoSec managers and IT admins about that issue. There's basically two camps: Actively block any new tool vs. not block but educate so people don't do a…

  6. comment
    Comment #41125029

    Indeed, when I learned about it I felt stupid for not having somebody run a regular report. Everybody talks about Shadow IT but most companies have a decent option to uncover a lar…

  7. comment
    Comment #41124615

    Good eye, but no, not related at all

  8. comment
  9. comment
    Comment #41123903

    Thanks! Any interesting findings?

  10. comment
    Comment #40081991

    Looks like a candidate for https://ssotax.org/friends-of-sso.html

  11. comment
    Comment #40081983

    Sounds like Tailscale is now a candidate for the "Friends of SSO" list https://ssotax.org/friends-of-sso.html Respect for pushing that through the org!

  12. story
  13. story
  14. comment
    Comment #35646938

    When talking about controls are you referring to provisioning? What are some examples for missing controls?

  15. comment
    Comment #35645051

    Do you have some examples on what granular controls are provided with Okta but missing with Google?

  16. comment
    Comment #35532743

    Great approach. Wish there would be more vendors like that. This way we wouldn't even need to talk about SSO-Tax, availability of SCIM/SAML etc.

  17. comment
    Comment #35528498

    Thanks! Happy to chat if you want to share some of the ideas you had

  18. comment
    Comment #35528478

    'Auditing user accounts in SaaS applications' is a pretty good summary of what the current version is about. The 'SSO-Tax' has become a synonym for the extra charges of SaaS vendor…

  19. comment
    Comment #35528308

    Great to see that we were not alone with the struggles! Let me know if you are up for a quick chat. Would love to learn more about your situation and how OpenOwl could help fix it.…

  20. comment
    Comment #35528278

    That's the spirit! Thanks for the kind words. Indeed, ease of use is incredibly important. After all this is a tool that needs to be used non-developer IT admins as well.

  21. comment
    Comment #35527994

    In future versions it will be possible to do the same with, for example, your Google SSO sign-in and 2FA enabled. The reason for the limitation is that we simply wanted to get it o…