The second speaker during keynotes at the Gartner IAM conference was Bruce Schneier who is chief security technology office for BT. The title of his talk was The Intersection of Identity, Privacy and Securityand it was fascinating. One comment that really struck home was about how organizations struggle with trying to implement RBAC at an enterprise scale. His point was that most businesses were so dynamic that the roles were constantly changing and would become un-managable very quickly. I call this “role proliferation” and it is pretty common to see scalability limits reached quickly in organizations using RBAC.
Recent Posts
- Automatically Provisoning and Deprovison Postini
- Visual Studio Lightswitch
- PING Identity’s Cloud Identity Conference
- Apple Bumper – they are kidding right?
- Use PowerShell to easly find Obsolete Accounts
- AD CMDLETS 1.4 now live!
- Microsoft KIN – RIP
- ActiveRoles User’s Groups Denmark & Sweeden
- Google Apps goes mutli-domain
- Review, Droid HTC Incredible, My First Week
- Death of the Incandescent bulb
- Droid Incredible, Verizon 3 Week Backorder
- AD CMDLETS Version 1.4 (Early look)
- Federation Service 2.0, now Shipping
- Just-in-Time Access Provisioning




Bob, what do you think is the solution giving the requirement of using RBAC?
There are several new technologies that are being used around validated attribute and policy that reduce or eliminate the need for RBAC. There are even on-going projects using these new Attribute Based Access Control systems to solve the scalability problems found in traditional the RBAC approach.