Gebäude der NLB Komerijalna Banka
NLB Komercijalna banka

Centralized Identity Management Instead of Fragmented Access Rights

Success Story6 min read
30+
Systems Integrated
3.500
Licensed Users
300
Roles Defined

A heterogeneous IT landscape and separately managed user accounts made access rights management increasingly complex for NLB Komercijalna Banka. Permissions were administered individually across different applications, without a centralized overview.

With Garancy, the bank consolidated user administration, established role-based access rights management, and created a single point of administration. The result: significantly fewer profiles, faster access provisioning, and greater transparency for security and compliance.

The Case at a Glance

  • Challenge: A heterogeneous IT landscape with decentralized access rights management created significant administrative effort and security risks.

  • Approach: Garancy centralizes identity management and consolidates individual user profiles into clearly defined roles.

  • Success: Around 3,500 historically grown profiles were reduced to fewer than 300 roles, while access for new hires and employees changing positions can be provisioned within seconds.

When Decentralized User Administration Becomes a Security Risk

NLB Komercijalna Banka’s IT landscape had grown increasingly heterogeneous over time. Different applications, mainframe systems, and Microsoft technologies had to be managed in parallel. Core systems included RACF, Microsoft Active Directory, and DB2.

Access rights were largely managed separately for each application. Administrators had to assign permissions individually, meaning new employees could wait several days before receiving all the access they needed.

There was also a security challenge: The bank lacked centralized visibility into which administrator had granted which permissions to whom and when. The bank therefore needed a solution that could consolidate user rights, establish consistent profiles, and centrally support security and compliance requirements.

A Single Point of Administration with Garancy

With Garancy, the bank established a single point of administration for identity management. Instead of managing permissions separately within individual applications, authorization processes can be controlled and tracked across systems.

Flexible integration was essential for the heterogeneous environment. Standard interfaces supported core systems such as RACF, Active Directory, and DB2, while uConnect provided flexible connectivity for individual applications.

Each of the three core systems was integrated within five days. User account consolidation and HR system integration followed.

From 3,500 Profiles to Fewer Than 300 Roles

The greatest impact came from consolidating the bank’s user and access structures. Previously, virtually every employee had an individual profile, with some having multiple profiles for different purposes. Garancy enabled the bank to standardize access assignment around typical job profiles.

Around 3,500 historically grown profiles were consolidated into fewer than 300 clearly defined roles. When employees join the bank or change departments, the connection between the HR system and Garancy allows the required application access to be provisioned through roles within seconds.

At the same time, the role model prevents employees from accumulating unnecessary permissions when their responsibilities change.

Vojislav Stojić , Head of Security Department, NLB Komercijalna banka

Garancy does away with the previous problem that employees changing their job roles accumulated access rights for many applications in an uncontrolled manner.

Vojislav Stojić
Head of Security Department

Reporting Creates Transparency and Traceability

Garancy provides detailed reporting on which administrator assigned which permissions to whom and when. Administrative activities therefore remain historically traceable and can be reviewed for audit purposes.

Centralized user administration also reduces the workload for IT. Processes that previously involved multiple administrators and individual systems can be handled more efficiently and consistently.

Results at a Glance

  • More than 30 integrated applications

  • 3,500 licenses for active users

  • Five-day integration time per core system

  • Around 3,500 profiles consolidated into fewer than 300 roles

  • Role-based access provisioning within seconds

  • Centralized reporting for greater transparency and auditability

  • Less manual effort in user administration

Centralized IAM for Greater Security and Efficiency

The NLB Komercijalna Banka success story demonstrates the impact of consolidating a heterogeneous access rights landscape. Garancy brings different target systems together within a centralized IAM structure and replaces individually grown user profiles with clearly defined roles.

This enables the bank to combine more efficient administration with greater transparency and better control over access rights – key foundations for security, compliance, and scalable identity management.

Further Resources

NBank Gebäude
NBank

Identity Management Starts with Expert Guidance

75
Systems Connected
1.000
Roles Created
< 5%
Rights Assigned Directly
Gebäude der KGAL GmbH & Co. KG
KGAL GmbH & Co. KG

Enhanced Security and Compliance with IAM at KGAL

Flexible Role Models
Automated Processes
Simplified Recertification

Let’s Talk Business!

Are you facing challenges in cyber security, automation, or compliance? In a compact strategy meeting, we will clarify which IAM approaches make sense for your company.

What you can expect:

  • Discussion of your individual requirements

  • Practical insights into our identity management software

  • Q&A and recommendations for the next steps

More than 6.16 million managed identities worldwide
A man in a white shirt, holding a yellow folder, smiles while speaking into a smartphone, standing beside a window with soft light.