Audit and compliance
Answer access questions from one record instead of six admin consoles, and export the evidence.
Access questions arrive with a deadline attached. An auditor asks who could reach a system in a particular month; a customer questionnaire asks how access is granted and removed; an incident asks who signed in and from where.
Answering from six admin consoles takes days and produces an answer you cannot really stand behind. The evidence either exists centrally or it is reconstructed, and reconstructed evidence is what fails a review.
What Besecure does about it
One record, not six
Sign-ins and administrative changes are written to a single audit log across every application published through Besecure, so an access question has one place to be answered from.
Reports you can hand over
Activity can be exported, so the answer to an auditor or a customer questionnaire is a document rather than a screenshot of an admin screen.
Controls you can point at
Sign-in can be restricted by IP address and by geography, alongside multi-factor authentication and a password policy set for your organisation — each of them a control you can demonstrate rather than describe.
Two of the Essential Eight
The ACSC Essential Eight names multi-factor authentication and restricting administrative privileges among its eight mitigation strategies. Besecure contributes directly to both. It does not address the other six — patching, application control, macro settings, application hardening and backups are someone else's job, and any vendor claiming otherwise is overselling.
Questions this usually raises
Does Besecure make us Essential Eight compliant?
No, and be wary of anything that says it does. The Essential Eight has eight mitigation strategies across three maturity levels. Besecure contributes to two of them — multi-factor authentication, and restricting administrative privileges through role-based access. The remaining six are about patching, application control, Office macros, user application hardening and backups, none of which an identity product touches.
What exactly is recorded?
Sign-ins and administrative changes, centrally, across the applications published through Besecure. Directory synchronisation runs are recorded separately with their status and record counts.
Can we get the data out?
Yes. Reports are exportable, so evidence can be attached to an audit response rather than described in one.
Other things teams use Besecure for
Contractors and third parties
Give external people a narrow, time-bounded slice of access that ends when the engagement does.
Customer and partner access
Give external users a narrow slice of access without turning them into unmanaged exceptions.
Employee SSO
One secure sign-in for every application your employees use.
Joiners, movers and leavers
Onboard from the directory you already run, and remove someone once rather than application by application.
Legacy and non-federated apps
Bring the applications that support no single sign-on behind the same launcher, the same roles and the same…
Privileged administrator access
Keep powerful access explicit, narrow and reviewable.
Replacing shared passwords
Model the accounts that genuinely have to be shared, instead of leaving them in a spreadsheet.
One sign-in for every app your team uses.
Set up your organisation, connect your directory and give your people a single secure launchpad.