Back

Controlling access based on role and/or location with ADFS

Access is one of those words that sounds simple but carries such farreaching implications that it must be carefully considered planned for and ma...

3 min read
Published on Dec 16, 2015
Controlling access based on role and/or location with ADFS

“Access” is one of those words that sounds simple but carries such far-reaching implications that it must be carefully considered, planned for, and managed at all times.

Questions to Answer Before Granting Access With AD FS

When planning access to information resources, there are several questions you must answer every time someone requests access.

  • Who is requesting access?

Are you certain they are who they say they are? Many tools exist that can increase your certainty. Multi-factor Authentication (MFA) is the strategy most people often think of. Here, information received from the user’s device is added to that person’s ID and password to increase the difficulty of requesting access. The information, usually a multi-digit number, changes every minute, so the user must possess the device and be able to obtain the number when logging in.

  • What is this user’s role in the organization?

There’s more to who you are than just your name. Roles-Based Access Control (RBAC) determines what resources each user has the right to access, and whether they can just read, read and write, delete, create, and change conditions and contents of each resource. Users may inherit certain rights when they are assigned to specific groups that have specific rights assigned, making it far easier to manage more users faster and more easily.

  • Which device is this person using to access resources?

You may want to reduce or restrict user access to certain resources based on the fact that they are using a smartphone or a personally owned device.

  • Where are they physically located when trying to access resources?

Some organizations only allow people to access highly sensitive data when located within their own premises (and not from outside) or on their corporate network directly rather than connected via an external network.

  • When is the user attempting to access resources?

Some organizations restrict access to business-critical resources only during regular business hours.  Anyone trying to access those resources outside of those hours will be refused, and the attempt will be reported.

Why You Want So Much Control

There’s much more to manage than ever before, and so many bad actors trying to steal and/or damage your valuable data resources. Failure to implement granular control over who can access what, when, and from where is like giving everyone the master key to every door. You simply can’t afford to do that any longer. It’s no longer enough to simply protect at the main gate; you must protect at the door to every room in every building.

How This Control Is Provided

You exercise control over your resources through Active Directory, the core database developed by Microsoft to provide one place to identify all objects and their relationships to one another. To accommodate the growing number of organizations that want to be able to interoperate with other organizations and still maintain tight control, Microsoft added Active Directory Federation Services to enable entire domains to interact.

The key to success in managing Active Directory and its Federation Services is to exercise control at the most granular level possible while grouping objects as much as possible to achieve greater efficiency.

Active Directory Agility from Agile IT

This is one of the main reasons customers choose to partner with Agile IT. Our expertise and experience in managing Active Directory for organizations large and small enables us to deliver the kind of guidance you need when planning, executing, and managing your Active Directory environment. To learn more about controlling access to your resources based on role, location, and much more, contact Agile IT today!

This post has matured and its content may no longer be relevant beyond historical reference. To see the most current information on a given topic, click on the associated category or tag.

Related Posts

OneDrive GCC High Migration: Step-by-Step Process

Steps to Migrate OneDrive to GCC High Environment

Follow this step-by-step guide to migrate OneDrive to GCC High securely and meet CMMC, DFARS, and ITAR compliance standards.

Dec 19, 2025
7 min read
Microsoft 365 Backup Access Control Best Practices

Managing Access Controls for Backup Data in Microsoft 365

Learn how to manage access controls for Microsoft 365 backup data. Protect sensitive data and ensure compliance with role-based permissions and audit logging.

Dec 18, 2025
5 min read
Why Hire an MSP for CMMC Certification Support

Why Hire an MSP for CMMC Certification Support?

Learn why partnering with an MSP for CMMC certification support can streamline your path to compliance, reduce costs, and improve cybersecurity posture.

Dec 17, 2025
7 min read
SharePoint GCC High Migration: Step-by-Step Guide

How to Migrate SharePoint Data to GCC High

Learn how to migrate SharePoint data to GCC High to meet CMMC, NIST, and ITAR compliance requirements with this practical guide.

Dec 15, 2025
7 min read
FedRAMP & Microsoft Cloud Tenant Migrations

Understanding FedRAMP Implications for Microsoft Cloud Tenant Migrations

Learn how FedRAMP requirements impact Microsoft cloud tenant migrations and what regulated organizations must do to stay compliant.

Nov 25, 2025
6 min read
Cloud Backup Strategies for Ransomware Protection

Protecting Against Ransomware with Cloud Backup Strategies

Explore effective cloud backup strategies to defend against ransomware attacks. Learn best practices for recovery, redundancy, and data resilience.

Nov 20, 2025
6 min read

Ready to Secure and Defend Your Data
So Your Business Can Thrive?

Fill out the form to see how we can protect your data and help your business grow.

Loading...
Secure. Defend. Thrive.

Let's start a conversation

Discover more about Agile IT's range of services by reaching out.

Don’t want to wait for us to get back to you?

Schedule a Free Consultation

Location

Agile IT Headquarters
4660 La Jolla Village Drive #100
San Diego, CA 92122