{"id":46499,"date":"2020-06-18T11:00:00","date_gmt":"2020-06-18T17:00:00","guid":{"rendered":"https:\/\/jumpcloud.com\/?post_type=resource&p=46499"},"modified":"2021-09-28T16:40:03","modified_gmt":"2021-09-28T20:40:03","slug":"case-study-chase-access-control-device-management-monitoring","status":"publish","type":"resource","link":"https:\/\/jumpcloud.com\/resources\/case-study-chase-access-control-device-management-monitoring","title":{"rendered":"Chase International Case Study: Access Control, Device Management, & Monitoring"},"content":{"rendered":"\n
Chase International<\/a> is a luxury real estate firm for properties in the Tahoe\/Reno\/Vegas area with more than $1.5 billion in annual sales. With 12 offices to manage and a remote work transition to navigate, Chase International\u2019s IT manager, Justin Price, wanted to select a directory service that would help the company remain agile and achieve regulatory compliance.<\/p>\n\n\n\n Justin Price is an IT veteran with more than 10 years of Active Directory\u00ae<\/sup> experience. When he came to Chase International in February 2020, the company didn\u2019t yet have a directory service in place, and user machines were unmanaged and unmonitored. Justin prioritized getting a directory service in place to remedy the fact that users were local admins on their machines and often shared passwords in their offices.<\/p>\n\n\n\n The process became more urgent when the company faced the COVID-19 pandemic and stay-at-home orders that forced all 12 offices of the organization’s office to move to a remote model. <\/p>\n\n\n\n Justin searched for a solution that he could use for access control, system management, and monitoring. With the arrival of the pandemic, he knew he needed an identity and access management (IAM) solution that wouldn\u2019t require on-premises infrastructure or VPNs to function correctly for a remote workforce.<\/p>\n\n\n\n \u201cThe COVID-19 crisis necessitated a breakneck turnaround on providing a suddenly remote workforce with an IT system that could manage user passwords, push applications and updates to computers, control group policies, provide IT with reporting information to monitor the information security environment, and do all of that from outside the office without the challenges associated with users trying to connect via VPNs to internal domain controllers or resources,\u201d Justin said.<\/p>\n\n\n\n That effectively ruled out AD. Justin didn\u2019t seriously consider Okta or Jamf either. The former had strong single sign-on (SSO) capabilities but couldn\u2019t serve as a standalone directory service for the organization, and the latter couldn\u2019t manage the organization\u2019s Windows machines or server. Instead, Justin wanted to find an all-in-one solution for access control and device management.<\/p>\n\n\n\n Justin was also interested in a solution with integrated tools to monitor his fleet of machines and return authentication logs as the company gears up for NIST 800-171 compliance, which will require records of who logged in, where they logged in from, and what they logged into, among other data.<\/p>\n\n\n\n Justin found 探花大神 Cloud Platform<\/a> and quickly made the decision that it would help the organization navigate the remote work transition and achieve regulatory compliance.<\/p>\n\n\n\n \u201cTo have everything in one place was awesome,\u201d he said. \u201cIt only took me about two weeks to make up my mind.\u201d<\/p>\n\n\n\n Justin first rolled out new systems to the organization’s full time employees \u2014 macOS\u00ae<\/sup> machines for the DevOps and executive teams and Windows\u00ae<\/sup> for the remaining users. He imported users from existing G Suite\u2122 and Microsoft 365\u2122 instances, sent them a 探花大神 activation email, and instructed them to download the 探花大神 agent on their new machines.<\/p>\n\n\n\n He could then deploy 探花大神 Policies to enable full-disk encryption and manage Windows updates, as well as begin monitoring the machines with System Insights\u2122. System Insights returns key data<\/a> about machines in a fleet, both through the web-based Admin Portal and via PowerShell and API, including hardware, software, and network configurations. <\/p>\n\n\n\n Because users are remote and Justin is running a lean IT department, he has users fill out a form if they need to download something, such as new software or a Google Chrome extension. He briefly grants them admin access on their machine and then runs a System Insights report afterward to verify they didn\u2019t take any other admin actions on their machine.<\/p>\n\n\n\n \u201cSystem Insights has been a lifesaver. It\u2019s made my job much easier.\u201d<\/p><\/blockquote>\n\n\n\n He\u2019s also begun to use Directory Insights\u2122 to collect data about user authentications and run queries. Directory Insights provides a 360\u00b0 view<\/a> of admin changes in the directory and user authentications to applications, systems, networks, and more. Justin plans to use the Directory Insights logs for NIST compliance, as well as to help the company decide whether they bring users back into their offices.<\/p>\n\n\n\n \u201cDo we want to stay with a fully remote workforce?\u201d Justin said. \u201cDo we want to do a hybrid? Or do we just want to bring everybody back in?\u201d<\/p>\n\n\n\n Justin has begun to roll out 探花大神\u2019s SSO portfolio<\/a>, as a variety of real estate and broker platforms use SAML connectors. He\u2019s also used 探花大神\u2019s cross-platform command runner<\/a> to deploy and execute commands on remote user machines.<\/p>\n\n\n\n \u201cThe commands feature has been incredibly useful,\u201d Justin said. \u201cI\u2019ve been watching YouTube tutorials to get back up to snuff with PowerShell scripting and terminal scripting. You don\u2019t really need anything else.\u201d<\/p>\n\n\n\n Justin has also enrolled the organization\u2019s macOS machines in 探花大神\u2019s Apple MDM<\/a> to be able to remotely lock, restart, shutdown, and wipe machines. He prioritized implementing the feature because the organization’s DevOps and executive teams, as well as Justin himself, use Macs.<\/p>\n\n\n\n \u201cWe have the keys to the kingdom, so if a Mac is stolen or lost I need to be able to kill it remotely to make sure our data is protected,\u201d Justin said.<\/p>\n\n\n\n Beyond the rollout of the core 探花大神 platform, Justin used the integrated cloud RADIUS feature to establish unique user logins to WiFi, which is particularly important for the segment of the company that handles financial data.<\/p>\n\n\n\n \u201cI finished the first RADIUS deployment, and it took less than 10 minutes,\u201d Justin said. \u201cThat was the fastest I\u2019ve ever done a RADIUS rollout.\u201d<\/p>\n\n\n\n Justin added that users have been receptive to the overall 探花大神 rollout because it\u2019s simplified their login process and helped them consolidate passwords.<\/p>\n\n\n\n \u201cIt\u2019s actually been very easy for them and very well received,\u201d Justin said. \u201cPreviously, there was no syncing, so their computer login would be different from their email. Without SSO, they\u2019d have all these different passwords for everything, so it\u2019s been very useful to consolidate everything.\u201d<\/p>\n\n\n\n Chase International is an umbrella for a variety of real estate services with 60 full time users and 400 real estate agents and brokers who work as independent contractors and who pay technology fees for basic services like email. Justin is proposing that contractors who pay increased technology fees are provided more IT services and management, which he could also accommodate from 探花大神. <\/p>\n\n\n\n Now that Justin has 探花大神 rolled out, he has time to step back and establish the organization’s first written policies. He plans to document policies for onboarding and offboarding, data retention, reporting, admin accounts, and eventually NIST compliance \u2014 as well as to systematically audit and ensure adherence to those policies across the organization. 探花大神 also enabled the team to stay safe and secure during a difficult time.<\/p>\n\n\n\n \u201cAlthough the last few months have been extremely challenging for our organization and employees, I cannot imagine what it would have been like without 探花大神 to bring everything together in such a complete manner quickly and efficiently, while also allowing us to do so from a safe distance,\u201d Justin said.<\/p>\n\n\n\n As compared to the costs of a traditional Active Directory instance<\/a> \u2014 including servers, licensing, and redundancy \u2014 探花大神 has been more effective and economical.<\/p>\n\n\n\n \u201c探花大神 continues to deliver a high return on investment for my department, my users, and the company as a whole.\u201d<\/p><\/blockquote>\n\n\n\n At 探花大神, we prioritize securing and enabling organizations \u2014 no matter where their users and devices are located. Our full-suite cloud directory service can serve as an organization’s identity provider and federate core identities to virtually all IT resources. Click here to learn more about the comprehensive access control and device management<\/a> you can achieve from the cloud.<\/p>\n","protected":false},"excerpt":{"rendered":" Chase International needed a directory service to manage users and devices and transition to remote work. Learn how 探花大神 helped.<\/p>\n","protected":false},"author":89,"featured_media":46502,"template":"","categories":[2337],"collection":[2780],"wheel_hubs":[],"platform":[],"resource_type":[2313],"funnel_stage":[],"coauthors":[],"acf":[],"yoast_head":"\n<\/figure><\/div>\n\n\n\n
Background: No Directory Service & COVID-19<\/h2>\n\n\n\n
IT Manager, Chase International<\/figcaption><\/figure><\/div>\n\n\n\n
\u201cIt was a priority from day one,\u201d he said. \u201cWithout directory services, there\u2019s really no way to manage your user base. Whether it was 探花大神\u00ae<\/sup> or Active Directory, something needed to be done.\u201d<\/p>\n\n\n\nChallenges: Unmanaged Users & Machines<\/h2>\n\n\n\n
Solution: All-in-One Cloud Directory Service <\/h2>\n\n\n\n
Implementation: \u2018Consolidate Everything\u2019<\/h2>\n\n\n\n
The Result<\/h2>\n\n\n\n
Learn More<\/h2>\n\n\n\n