A Fortune 1000 automotive company with roughly 300 IT staff across the US and Europe had no privileged access management. Nearly everyone in IT carried a second account with standing privileges, teams held blanket access to services they rarely used, and the company could not say who was able to reach what. Admin account usage was growing faster than the team's ability to govern it.
With Venice, the company replaced those standing accounts with Just-in-Time access governed by Venice and, for the first time, has a complete inventory of its identities and servers. Production environments, including a GDPR-compliant instance for Europe, were live 48 hours after signature, and every user identity was managed by Venice within a week.
The problem: A second privileged account for everyone
The company had grown fast, and standing access had grown with it.
“Almost everyone in IT carried a second account with standing privileges, and entire teams had blanket access to services they touched maybe once a quarter,” the company's Director of Infrastructure said. “Our systems group had more access than anyone in the organization. On any given day, we could not have told you exactly who was able to reach what.”
On any given day, we could not have told you exactly who was able to reach what.
Director of Infrastructure
“When we scoped the timeline, my answer was: secure it yesterday,” the company's Director of Identity and Access Management said. “Usage was growing faster than our ability to govern it.”
The goal was set from the start: get rid of standing access on everybody's personal accounts.
The complication: Europe
The company's European operations fall under GDPR, so privileged access data for European users had to stay in Europe. That meant a second, separate environment. In a PAM deployment that installs agents and integrations per environment, a second environment is a second rollout: its own infrastructure, its own agent deployment, its own directory and identity provider integrations, and its own testing. That is why a single data-residency requirement typically adds months to a PAM project.
The rollout: Live in two days, every identity in a week
The contract was signed on a Thursday. Roughly 48 hours later, Venice was running in production in three environments: a GDPR-compliant instance for Europe and two US data centers, each able to grant privileged access to the servers in its region. Okta and Active Directory were connected next, and within five business days every user identity in the company was managed by Venice. The largest single push onboarded 120 servers in under 12 hours.
None of this required installing software on a server. Venice is agentless, so servers are onboarded without a change-management window for each one.
“We signed the contract and had production environments running in about 48 hours, including a GDPR-compliant instance for Europe,” the company's Deputy CISO said. “I have run infrastructure projects where scheduling the kickoff meeting took longer.”
I have run infrastructure projects where scheduling the kickoff meeting took longer.
Deputy CISO
The results: No more standing admin accounts
Discovery came first. In the first week, Venice mapped more than 113,000 identities and 35,000 servers across the environment. A company that could not say who had access to what now had a complete inventory of both.
With the inventory in place, the second privileged accounts were retired. Standing access on personal accounts is replaced with per-group access governed by Venice: requested, granted for a fixed window, logged in full, and revoked when the window closes.
“The goal was to get rid of standing access on everybody's personal accounts,” the Director of Identity and Access Management said. “For the first time we have a real inventory of our identities and servers, and a way to grant access only when someone needs it, for only as long as they need it. We went from no privileged access management to enterprise-grade within a week.”
We went from no privileged access management to enterprise-grade within a week.
Director of Identity and Access Management