Automating the Cleanup of Inactive Identities in IBM Cloud

11:57 pm
September 29, 2023

Inactive identities can pose a security risk in any environment, including cloud environments. In a blog post, IBM Cloud explains how to identify and handle inactive identities using the APIs provided by IBM Cloud Identity and Access Management (IAM).

After receiving feedback from readers on how to proceed after identifying inactive identities, IBM Cloud provides steps for automating the cleanup process. These steps include revoking privileges, removing identity types from the account, and scripting and automating administrative tasks.

Recap: Inactive Identities

IBM Cloud IAM supports different forms of identities such as users, service IDs, and trusted profiles. If an identity or associated API key has not been used for a certain period of time, it is considered inactive. IBM Cloud IAM provides functionality to create reports on inactive identities.

To improve security, it is recommended to revoke access privileges from inactive identities and potentially remove them from the cloud account. However, there is an operational risk with special identities used for quarterly or annual processing. In such cases, it is important to keep track of how inactive identities and their privileges are cleaned up.

Automated Cleanup

Cleaning up inactive identities can be done manually, but automating the process is more efficient and improves security. The suggested steps for automated cleanup include generating a report on inactive identities, checking against a list of exempted IDs, removing the identity from all access groups, and deleting associated API keys.

Logging the findings and actions taken for audit and improvement purposes is essential. The frequency of cleanup (monthly or quarterly) can be determined based on corporate policies. It is recommended to maintain a list or database of identities that are excluded from cleanup to avoid removing important identities.

Users, Service IDs, and Trusted Profiles

In addition to revoking privileges, it is also recommended to consider deleting unused service IDs and trusted profiles, as well as removing users from the account. By periodically listing all users and checking their states, invalid or suspended users can be removed from the account.

IBM Cloud provides APIs to remove users from an account, delete service IDs and their associated API keys, and delete trusted profiles.

Conclusion

Regular account cleanup is important for both account administration and security. Automating the cleanup of inactive identities in IBM Cloud helps improve security and efficiency. However, it is necessary to maintain logs and exempted identities to avoid disrupting applications and workloads.

FAQ

1. What are inactive identities in IBM Cloud?

Inactive identities in IBM Cloud are identities (such as users, service IDs, and trusted profiles) or associated API keys that have not been used for a specific period of time.

2. What is the risk of inactive identities?

Inactive identities pose a security risk as they may no longer be maintained and can be easier to attack. Revoking access privileges from inactive identities and removing them from the cloud account helps improve security.

3. How can the cleanup process for inactive identities be automated?

The cleanup process for inactive identities in IBM Cloud can be automated by generating a report on inactive identities, checking against a list of exempted IDs, removing the identities from all access groups, and deleting associated API keys. It is also important to log the findings and actions taken for audit and improvement purposes.

4. What actions should be taken after revoking privileges from inactive identities?

After revoking privileges from inactive identities, it is recommended to consider deleting unused service IDs and trusted profiles, as well as removing users from the account. By periodically listing all users and checking their states, invalid or suspended users can be removed from the account.

5. How often should the cleanup process for inactive identities be performed?

The frequency of the cleanup process for inactive identities can be determined based on corporate policies. It is recommended to clean up monthly or quarterly and maintain a list or database of identities that are excluded from cleanup to avoid removing important identities.


Share:

More in this category ...

7:27 pm April 30, 2024

Ripple companions with SBI Group and HashKey DX for XRPL answers in Japan

Featured image for “Ripple companions with SBI Group and HashKey DX for XRPL answers in Japan”
6:54 pm April 30, 2024

April sees $25M in exploits and scams, marking historic low ― Certik

Featured image for “April sees $25M in exploits and scams, marking historic low ― Certik”
5:21 pm April 30, 2024

MSTR, COIN, RIOT and different crypto shares down as Bitcoin dips

Featured image for “MSTR, COIN, RIOT and different crypto shares down as Bitcoin dips”
10:10 am April 30, 2024

EigenLayer publicizes token release and airdrop for the group

Featured image for “EigenLayer publicizes token release and airdrop for the group”
7:48 am April 30, 2024

VeloxCon 2024: Innovation in knowledge control

Featured image for “VeloxCon 2024: Innovation in knowledge control”
6:54 am April 30, 2024

Successful Beta Service release of SOMESING, ‘My Hand-Carry Studio Karaoke App’

Featured image for “Successful Beta Service release of SOMESING, ‘My Hand-Carry Studio Karaoke App’”
2:58 am April 30, 2024

Dogwifhat (WIF) large pump on Bybit after record reasons marketplace frenzy

Featured image for “Dogwifhat (WIF) large pump on Bybit after record reasons marketplace frenzy”
8:07 pm April 29, 2024

How fintech innovation is riding virtual transformation for communities around the globe  

Featured image for “How fintech innovation is riding virtual transformation for communities around the globe  ”
7:46 pm April 29, 2024

Wasabi Wallet developer bars U.S. customers amidst regulatory considerations

Featured image for “Wasabi Wallet developer bars U.S. customers amidst regulatory considerations”
6:56 pm April 29, 2024

Analyst Foresees Peak In Late 2025

Featured image for “Analyst Foresees Peak In Late 2025”
6:59 am April 29, 2024

Solo Bitcoin miner wins the three.125 BTC lottery, fixing legitimate block

Featured image for “Solo Bitcoin miner wins the three.125 BTC lottery, fixing legitimate block”
7:02 pm April 28, 2024

Ace Exchange Suspects Should Get 20-Year Prison Sentences: Prosecutors

Featured image for “Ace Exchange Suspects Should Get 20-Year Prison Sentences: Prosecutors”
7:04 am April 28, 2024

Google Cloud's Web3 portal release sparks debate in crypto trade

Featured image for “Google Cloud's Web3 portal release sparks debate in crypto trade”
7:08 pm April 27, 2024

Bitcoin Primed For $77,000 Surge

Featured image for “Bitcoin Primed For $77,000 Surge”
5:19 pm April 27, 2024

Bitbot’s twelfth presale level nears its finish after elevating $2.87 million

Featured image for “Bitbot’s twelfth presale level nears its finish after elevating $2.87 million”
10:07 am April 27, 2024

PANDA and MEW bullish momentum cool off: traders shift to new altcoin

Featured image for “PANDA and MEW bullish momentum cool off: traders shift to new altcoin”
9:51 am April 27, 2024

Commerce technique: Ecommerce is useless, lengthy are living ecommerce

Featured image for “Commerce technique: Ecommerce is useless, lengthy are living ecommerce”
7:06 am April 27, 2024

Republic First Bank closed by way of US regulators — crypto neighborhood reacts

Featured image for “Republic First Bank closed by way of US regulators — crypto neighborhood reacts”
2:55 am April 27, 2024

China’s former CBDC leader is beneath executive investigation

Featured image for “China’s former CBDC leader is beneath executive investigation”
10:13 pm April 26, 2024

Bigger isn’t all the time higher: How hybrid Computational Intelligence development permits smaller language fashions

Featured image for “Bigger isn’t all the time higher: How hybrid Computational Intelligence development permits smaller language fashions”
7:41 pm April 26, 2024

Pantera Capital buys extra Solana (SOL) from FTX

Featured image for “Pantera Capital buys extra Solana (SOL) from FTX”
7:08 pm April 26, 2024

Successful Beta Service release of SOMESING, ‘My Hand-Carry Studio Karaoke App’

Featured image for “Successful Beta Service release of SOMESING, ‘My Hand-Carry Studio Karaoke App’”
12:29 pm April 26, 2024

SEC sues Bitcoin miner Geosyn Mining for fraud; Bitbot presale nears $3M

Featured image for “SEC sues Bitcoin miner Geosyn Mining for fraud; Bitbot presale nears $3M”
10:34 am April 26, 2024

Business procedure reengineering (BPR) examples

Featured image for “Business procedure reengineering (BPR) examples”
7:10 am April 26, 2024

85% Of Altcoins In “Opportunity Zone,” Santiment Reveals

Featured image for “85% Of Altcoins In “Opportunity Zone,” Santiment Reveals”
5:17 am April 26, 2024

Sam Altman’s Worldcoin eyeing PayPal and OpenAI partnerships

Featured image for “Sam Altman’s Worldcoin eyeing PayPal and OpenAI partnerships”
10:55 pm April 25, 2024

Artificial Intelligence transforms the IT strengthen enjoy

Featured image for “Artificial Intelligence transforms the IT strengthen enjoy”
10:04 pm April 25, 2024

Franklin Templeton tokenizes $380M fund on Polygon and Stellar for P2P transfers

Featured image for “Franklin Templeton tokenizes $380M fund on Polygon and Stellar for P2P transfers”
7:13 pm April 25, 2024

Meta’s letting Xbox, Lenovo, and Asus construct new Quest metaverse {hardware}

Featured image for “Meta’s letting Xbox, Lenovo, and Asus construct new Quest metaverse {hardware}”
2:52 pm April 25, 2024

Shiba Inu (SHIB) unveils bold Shibarium plans as Kangamoon steals the display

Featured image for “Shiba Inu (SHIB) unveils bold Shibarium plans as Kangamoon steals the display”