When Manual Access Rights Management Reaches Its Limits
As MULTIVAC grew, the increasing use of digital services and rising compliance requirements also placed greater demands on its Identity & Access Management. The existing solution primarily managed Windows AD identities and, to a limited extent, SAP identities, but did not provide comprehensive authorization management.
Access requests and provisioning were handled via tickets, emails and phone calls. At the time, there was no consistent, centrally managed process in place. This required considerable staff resources and made centralized evaluation and tracking more difficult. The transition from Lotus Notes to Microsoft Outlook, along with the migration of key applications to the cloud, ultimately prompted the search for a new IAM solution.
Following a tender process and the evaluation of several providers, MULTIVAC selected Garancy.
The Garancy Identity Manager met more of our requirements than any of the other solutions we evaluated. The decisive factors were its broad functional coverage and the flexibility of the solution, combined with a strong focus on standardization.
:quality(50))
Standardized Roles as the Basis for Automation
A key part of the transformation was the development of a role concept. Previously, outside individual SAP areas, access rights were often assigned as needed without an overarching structure. Together with Garancy, MULTIVAC analyzed existing user permissions and gradually derived suitable roles from them.
Today, roles are generated based, among other things, on the combination of department and job position. Basic access rights are defined together with the respective department managers. Additional roles for specific applications and functions can increasingly be requested directly via the Garancy Self-Service Portal.
Find out how the role concept was developed in detail and how role mining contributed to the process in the full customer success story.
Around 20 Systems Centrally Managed Through IAM
With Garancy, MULTIVAC manages accounts and access rights across Windows AD/Entra, various SAP instances, the USU ITSM solution and an internal simulation system for machine configuration, among others. Around 20 systems are connected in total.
Role definitions, automation and HR imports enable MULTIVAC to standardize the assignment of access rights. Departmental roles can now be assigned automatically, improving the consistency of permissions while reducing administrative effort. Despite the company’s growth, MULTIVAC has been able to avoid the need for additional staff in authorization management.
Greater Traceability for Compliance and Audits
Centralized authorization management also offers advantages in terms of documentation and compliance. Instead of handling access requests through different channels, the relevant processes can now be tracked centrally – providing valuable support for the MULTIVAC Group during audits.
Key considerations include ISO 9001 requirements, alignment with ISO 27001, and regular audits in the SAP environment. As part of the ongoing development of its authorization management, MULTIVAC is also working with Garancy to introduce the Recertification Center. The aim is to further standardize and automate the regular review of access rights.
Read the Full Customer Success Story
How did MULTIVAC transform predominantly manual workflows into standardized authorization management for up to 8,000 users? What role do role mining, automated role assignments and the integration of different systems play?
The full success story provides insights into the IAM project and shows how MULTIVAC developed its role concept, automated processes and created the foundation for greater transparency in compliance and audits.
:quality(100))
:quality(100))
:quality(100))
:quality(100))
:quality(80))