Authorization in IAM – Mickey Martin, PlainID
Transcript
This is texturing TV. Hey everyone, welcome back to techstrung TV. I'm happy to introduce you to well, it's his first time on our show.
He's Mickey Martin and Mickey welcome to techstrong TV. Hey, thank you very much. I you know like you said this is the first time I've been on here and I'm super excited to be able to do this take strong.
So it's been something I've paid a lot of attention to so appreciated where we're excited to have you on so Mickey. I didn't even mention company name your title Your Role why I'm gonna let you tell the story man. Give us your give us the Mickey Martin story.
All right. Yeah, so, my name is Mickey Martin. My my current role is I am the director of product Outreach at a company called plain ID for myself.
I've been an identity and access management for about 12 years now, which is a long time for someone my age. I've literally done it. My entire career first job out of college was at Indiana access management project for for Department of Homeland Security at one point in time.
But plain ID the company itself, we like to pride ourselves and calling ourselves. The authorization company authorization is what we focus on authorization Access Control. And we focus on you know, providing a centralized management and distributed enforcement of your authorization and your policies all throughout your ecosystem while being powered by you know, we use P back inside of playing ID.
So policy based Access Control, you know, we like to pride ourselves and also saying that authorization is the thing that gives you access, you know, a lot of people like to say authorization. That's the thing that blocks me every time I try to do something and I like the joke that you know, no security already decided. Nobody does anything zero trust, right?
But nobody does anything authorization and access control is the map. It's it's the rules. It's the map.
It's the details on how a person a digital Identity or even a microservice gets access to a digital assets. com right not playing like an airplane. Yeah, it's actually playing as in plain language.
So one of the things about tools is that when you're writing policies themselves, you can write them as code like if you're developer, but at the end of the day the business teams and security teams actually get to see the policies in plane language plan English. That's where the plain side comes over. That's where we make sure that the business team and the security team actually understands how authorization how access control is control of the entire ecosystem.
Got it. I'm good. I'm glad we got that out of the way.
So, you know Mickey as you mentioned. Maybe prior to the cloud like 2005-2006. the world of identity and access management IAM or IAC It was a much easier or not easier because it was never easy.
It was a much simpler. World where I only had to worry about what you did in my land, even if you came in via the VPN. Right to go back out you you still like I controlled.
I controlled that castle with the motor around it, right and and so in that motion Castle world. Identity and access management was frankly with something. I did an act of directory and it was a pretty easy thing to do.
You know wasn't rocket science. Let's say Then with the Advent of cloud, you know we started going. Of places where we didn't really have total control.
Let's call it and we started going to a lot more places right one cloud provider SAS providers here there everywhere covid and we all work from anywhere. We do anything from anywhere where we're really distributed now, and I think one of the things that we've seen is sort of I am breaking into I am and am or AC right Access Control. versus identity identity there's a whole series of issues with identity, right we and it's in the to the newspapers.
Unfortunately every week, right? Access or authorization as you called it access control and access management. Is a much.
Well, it's it's connected to Identity obviously, but it is it's it's own. Kind of thing these days right? It's own world with his own set of challenges even independent of the identity piece of it.
Talk to us about that a little bit. Yeah. Yeah, so I would say one of the biggest challenges about authorization itself is sometimes it gets it's overshadowed by the identity world and the identity part is part of it.
Right if I'm going to decide what a user can and can't do an assistant. I need something to to identify the user 12 indicate the user to challenge them and make sure they own that digital account but everything after that is what can you do now that I know who you are, you know, the simple example always uses because they think it's the same but it's not when you give your ID to a person at a bar right identification authentication. That's when they looked at your idea and decided it's real everything after that's authorization whether or not you're 21 whether or not you should buy alcohol.
That's authorization. They did any space is the same way. We see that identity side of the house and it's big and it's huge and there's a lot of things going on into it and I think what has happened in the last few years because of this Cloud expansion because of digital identity is going to digital Transformations and becoming bigger.
It had to be its own thing. You know, it couldn't be that moat and Castle anymore. It got so That it had to be its own thing.
I didn't even had to be put over here and manage a different way. And we also had to do the same thing with authorization. But what we've currently done with authorization is we've forgotten that we buried all of that authorization logic deep inside of the applications themselves, you know something that we also used to do in that moat and Castle world when we had these monolithic applications, we would take that authorization logic and then we would bury it down into the application and it would all be custom code that was written by you know, I'm developer and I would say the spotlight the identity side did right.
I didn't get the spotlight that authentication got because it was buried it was you know, so deep inside of a monolith and you know five or six people in the company knew about it. That's Spotlight now and why is it changing now is because like you said that moved to the cloud environment that distributed environment that distributed Workforce. We started breaking down these monoliths into thousands of tiny little pieces and thousands of tiny little services like and it started being very hard to keep an eye on how does a user actually get to do things in my system.
It started becoming very hard to decide. Hey, I can authenticate Mickey but what was that path that allowed make you to change that record inside of my database, you know old days the monolithic world, right? Oh, they went to that one single application or they went directly the database that was it's easy for me to go nowadays.
You have a thousand micro Services across multi, you know multi-cloud environment. You have thousand rest apis across the multi-cloud environment that needs to be visible needs to be centrally managed because otherwise you won't have a hand alone. Absolutely.
Okay, no good. I I agree. I mean one of the things Mickey was.
In the old way I didn't care where you went within the castle because I had that single choke point. Right where and that and that was like the big benefit or the bigger lore of DLP, which is probably a security technology that never lived up to the hype. But the idea was look you could go wherever you want inside here, but I'll be damned if I'm gonna let anything go out, right and I'm gonna inspect, you know, sort of a reverse Customs and Border control.
I'm gonna inspect everything going out making sure you're allowed to take that out. Once you once you break out of the castle and we have assets all over that whole paradigm. You know goes to hell in a ham bucket.
You just don't it don't work. So, you know, we obviously had to do just a whole different take on this. Now I totally agree.
I think this distributed Workforce and then opening up to to the outside world it really it really showed us how much we hid behind our firewalls. Yeah. It really did No Doubt.
And and I think that's what's driving some of the trends that we're seeing today, right that that started showing us how much we were hiding behind our firewalls and then people started going. Well. I feel like I have authentication down.
What am I missing? You know, I did all of this work in the eye part of identity and access management, but you know, I feel I still feel like I have a you know a secure policy or still don't feel like I have a handle on things one of my missing what's the authorization it's the access side of the house and I think that's why we're seeing some of these Trends where you know, the c-suite right now the 62% of them are looking at real time access because I know that's the other side of the paradigm. They're also you know, they're looking at Payback.
And one thing I like to say about peaback is that you know, if you if you go through a couple of things, there's like three different p-backs out there right now, there's purpose-based access control. So for this, you know what I'm talking about it I do mean policy based access control, which is a strategy provided by nist for controlling access itself, you know, not just focusing on ACLS and not just focusing on our back Ray back and age an entire strategy that covers your entire company ecosystem. So I think that's why we're seeing those, you know, those drivers pop up now.
Yeah, I think zero just drives a lot of it too is you know, it's it's such a different. View of the world where you say, look I'm I know you're Mickey. I'm giving you access to the whole enchilada here, right and and you know, because I trust you Mickey, right?
You're one of our workers or your valued third party or whatever. And and then what I'll do is I'll start shutting things down. Are they dads needed bases that you don't really need access to?
Right, I'll start limiting your access that way versus a zero trust mode of hey, I don't care whether you're Mickey or the Man in the Moon. You only need access to these things and by default everything else is shut down. Right and and it sounds great sounds really easy, right you'd sign up for that in a second the doubles in the details here a lot.
So let's hear about you know plain idea and how you guys help with the devil in the details. Yeah, yeah, so so with zero trust itself, you know, one of the big pieces that I think a lot of companies are missing is identity First Security. And the reason I say that is because you know, we like to say identities the center of everything but Friday to be in this Center of everything you have to connect it everything.
Like I said at the beginning authorization is that connective tissue? So with that identity First Security, you know, you're for a lot of people are trying to adopt that model, but they're starting to realize deeper down, you know as we go down that technology stack from the application to the apis and we start going to that microservice layer and that everything starts getting real fuzzy with that identity. Right?
So now if you look at zero trust zero trust as you have to reevaluate Trust at every digital interaction. Well, if I'm going to reevaluate the trust of an individual at every digital interaction, I need to know the individual. I need to have identity First Security.
Right. I also need an ability. A platform usually that can control authorization centrally.
But make sure that at each step at each piece of technology that that digital interaction takes place in it's enforced appropriately. So those two things kind of go hand in hand, like a lot of people zero dress identity for security. They go hand in hand.
You can't get zero trust without identity for security because I have to reevaluate trust, you know to evaluate trust. I gotta know who I'm dealing with. Now that's where authorization itself comes in right because where are you going to reevaluate that trust?
You of course, you do it at every interaction but authentication happens once, you know once per day if you're lucky if you're if you're a Siam or retail vendor that might be once every five years that you make your customers login crossing the firewall the of course, you should do it there. But that happens right times. How many firewalls do you cross as you're as you digital interactions?
But as I'm using your services as I'm transferring money as I'm looking at my bank accounts as I'm doing audit records. That's hundreds of digital interactions. And the only way to reevaluate trust that those digital interactions is to have it built into your authorization strategy.
So that is where a plane ID comes in, right? So plan ID is a platform. Like I said to centrally manage all of this so that you can write your policies.
Once you can write your policies and playing English that allow you to say. Hey a user can only you know move money that belongs in their account. If their risk level is a certain threshold.
You know if they've used multi-factor, we don't enforce multifactivists. They authentication is providers, you know, and if it's not risky for the user themselves, we can take in things like behavioral risk. So all of those things that you want to use to reevaluate trust you can have built into the authorization itself, and then you can allow the platform to reevaluate that trust at every stage.
So when the call comes from the app to the API when it goes from the API to the micro service you can reevaluate that trust at every level. Utilizing plane ID which also allows you to step up your or I would say step down your tolerance. You know, you want to tolerate less risk the lower that interaction goes That becomes very important because once you get lower and lower, you know what the user's intentions are which gives you a better risk evaluation right when I log into my bank account, and I'm just looking at my bank information.
Yeah, there's some risk you want to to evaluate whenever I'm trying to log in and a lot of times you'll tolerate a little more risk. I'm just looking at thank information. Now, let's talk about digital interactions.
I want to transfer money. That's where authorization kicks in I'm going to tolerate less risk during a transaction time than I do it authentication time. All of that is rolled into authorization.
So I know that's a lot of functionality pieces, but I know we have some technical members that are that are paying attention on here. Yeah. No, our audience gets it and and it really is I mean This is the way I mean.
If you want to make it done and I mean the word the way I'm using it if you want to dumb it down. It's for a very simple. World and we don't live in a simple world.
So You don't work, so it's all good there. So that's okay. I sorry appreciate you coming in and talking about this what's going on new with at plain ID that maybe folks want to go check out.
Yes, so some of the new things that we have going on at playing ideas. We just released a new version of our platform previously since the last time playing that he's been interviewed on here. We released a full SAS version of our platform which our users can go in and play with and consume and then we've also released a new version of our on-premise product for our customers who want to make sure that all of these interactions happen behind their firewall.
Some big highlights with those new releases comes in the comes in the release of our authorizers. So what our authorizers do is it is their job to take your policies and enforce them in the technologies that you install them in. We're trying to take away as much custom code development as as possible for a company.
So when you write a policy that says, hey users aren't allowed to see certain data. You don't have to go right custom code that consumes that policy you can actually use one of our authorizers and install it directly into your data access layer or you know, your API layer and let the authorizer worry about interacting natively with those digital assets and blocking them or allowing the access to it. So that's some of the major things that are coming out.
Different minor things, we now support policy as code as much as the business teams and the security teams are involved in writing policies and authorization policies. We've we know that a lot of times policy starts with the developer, right they develop the application and they also develop, you know, the logic itself. So we support policy as code analysis developers can actually write policies in their native, you know, in this case we're using Rego lean right in their native way imported into the platform and then businesses can still consume all of the other pieces of plain ID, which is like policy investigation approval workflows, testing auditing across their entire ecosystem.
They still get all of that benefit while allowing, you know developers right policies in the way. They like to write policies. Very cool.
Very cool. Hey Mickey, we're out of time. I want to thank you for coming on and making us a little smarter here.
on this I do think at the end of the day. The whole like bifurcation if you will have identity from access is something that a lot of organizations are still trying to wrap their heads around right? I think they unfortunately too many of them just still say I am and leave it at that.
So hopefully man, you know, you got your work cut out you got to go out there and preach right but get people smart on it and make it happen and come back and see us. That's an exciting time for authorization. And again, thank you for for the opportunity to speak today.
All righty. Hey Mickey Martin from plain ID here on techstrunk. We're gonna take a break.
We'll be right back.