Tag: IT administrators

  • Tips for Modern IT Admins’ Career to the Cloud

    Tips for Modern IT Admins’ Career to the Cloud

    Fifteen years ago IT professionals experienced a drastically different day-to-day on the job. While the main mission has always remained constant—to take charge of all internal infrastructure—the infrastructure itself has moved off-premises over time.

    The complexity rested in networking for IT professionals. Routers, switches, firewalls and other gear needed to be managed so the network would function. Employee devices also required attention from IT admins, but these devices were typically all Microsoft Windows machines. This allowed IT to standardize its tools and platform.

    What Has Changed for IT Admins?

    Time has drastically altered the lives of IT admins and, after 15 years of evolution, organizations have moved away from large, ungainly on-premises networks and data centers. However, the list of endpoints for infrastructure has grown rather complex, specifically as a result of the implementation of different platforms and operating systems.

    The challenges faced daily and the knowledge needed to be successful has exponentially grown. Below we will take a deeper look at three of the larger changes that IT professionals must ponder as they elevate their careers in the burgeoning cloud environment.

    Rethinking Networking

    The time when it was important to know how to configure a router or switch is slipping away. In the modern IT world, this task has been adopted by cloud infrastructure providers such as AWS and GCP, as well as the telecom companies that deliver your internet.

    The job for IT admins has leveled up, as now it is vital to know how to manage and configure the higher levels of infrastructure. The ability to route traffic through security groups and automate the configuration of systems is a necessity. Writing code to automate these tools is now the norm for an IT admin.

    Regulating Employee Wants

    In the past, IT could dictate the tools that employees had to use, but that ship has sailed. Employees have begun to adopt their own tools to further maximize their efficiency, which forces IT to adapt and get ahead of the game.

    It is crucial to show employees both flexibility and confidence when leveraging new technologies. As a result, employees will work with you and not go out and create shadow IT projects.

    Seeking out and securing cross-platform tools that allow you to manage the various endpoints and services your team is leveraging is of the utmost importance. These tools do exist; however, they typically are not offered by traditional vendors such as Microsoft, HP and Oracle.

    Security is the No. 1 Concern

    Not long ago, security for IT admins was simply firewalls and anti-virus solutions. Fifteen years later the world of IT security is far more intricate.

    To be successful in the IT world, an admin needs to be an expert at infosec so they can understand and defend against the massive world of cybercriminals. Identity theft is rampant and hackers are always trying to locate vulnerable systems that have not been patched. It is because of this that IT admins need to be constantly on their toes and protecting their organization.

    IT is the Core of an Organization

    Without IT, business simply wouldn’t get done. Sales would not be able to email contracts, products would go undelivered, customers would go unbilled and other core activities would fail.

    The IT admin is a vital part of every organization, which is why they are in high demand today. Mastering new technologies and understanding the constantly evolving approaches to IT can be the difference between an organization falling flat on its face or leading an industry.

    — Rajat Bhargava

  • How Can IT Admins Maintain a Grip on Secure Access?

    How Can IT Admins Maintain a Grip on Secure Access?

    Today’s IT environment is evolving at a rapid pace, requiring production environments to be highly scalable and elastic and requiring faster software release cycles and cloud adoption.

    As a result, there’s a broad move toward Docker containers to make software deployment faster, easier and more consistent across computing environments. Bundling an application and its supporting code, libraries, settings and assets into a single container enables the speed and flexibility that today’s business environment demands.

    At the same time, many large enterprises are also experimenting with creating internal startups, or labs, that are given latitude to innovate, housed under the company umbrella and resources. Similarly, some companies are hosting startup-like “innovation incubators,” where developers are empowered to think and work like startups, within the relative safety of the corporate environment. They can quickly test new ideas, using the “fail fast, succeed fast” startup mentality, without incurring the usual risks of an independent startup.

    It’s a new agile way of working that companies, in the race to innovate, are widely embracing. In fact, more than half of Fortune 500 companies have some version of these startup-like efforts housed within at least one business unit. 

    Replicating the unstructured movement of a small–say, six-person–startup is difficult to do within an enterprise environment. Nevertheless, the rapid pace, combined with the flexibility to innovate, is what the vast majority of developers desire today. But, it does mean that enterprises’ IT environments have to be ready to adapt.

    IT Administrators Under Pressure

    Developers on these innovation teams are often given the freedom to select the tools they’d like to work with. That can–and often does–include Docker containers, which adds to the complexity of the IT environment. 

    The environment that fuels developer innovation also creates additional concerns for the IT administrators supporting them. Developers can work so rapidly–creating hundreds of new servers each day–but often only do the bare minimum in terms of security. How can IT admins maintain secure access in the face of these changes? How can they keep track of who has access to what application and what data, when those applications and data are constantly changing? That’s a massive issue when it comes to compliance.

    As containers make enterprise IT environments even more complex, IT admins are under pressure to carefully manage access without slowing down development. The more complex the environment becomes, the more important it will be to have a holistic view of all of their underlying infrastructure, including the hybrid or multi-cloud environments that support platforms such as Docker and Kubernetes.

    Meanwhile, the enterprise executive team, often the CISO, overseeing both the development and IT departments is hard at work trying to satisfy the requirements of both groups. Of course, it’s in the business’s best interest to innovate and explore. But, all that innovation means nothing if the business is no longer secure and open to compliance concerns.

    Below are three steps executives should follow in order to keep their developers and IT admins happy.

    Consider the Developer Experience for Secure Access

    Off-the-shelf single sign-on solutions (SSO) may be good enough for business employees who need to access Outlook or Salesforce, but they aren’t robust enough for privileged IT users, like developers, who need to access secure environments. 

    Privileged access management (PAM) software sprung up to serve IT users, but even this isn’t a perfect solution, because traditional PAM tools are often too clunky to use, nonintuitive, or hard to configure. A bad user experience simply encourages developers to bypass PAM however they can, which is a compliance risk.

    Businesses need a way to deploy secure access very quickly, so they can holistically manage access to critical IT resources without slowing down development. That means choosing secure access solutions that are built with the developer’s needs in mind.

    Lean PAM solutions prioritize automated, instant access to secure IT environments with the click of a button, combining the convenience of modern SSO solutions with the security and fit of a PAM solution. If sysadmins have a great PAM user experience, they’re more likely to play by the rules. 

    Opt for Role-Based, Time-Bound Access

    To maintain the highest levels of security, access must be controlled on a role-by-role basis. Your rock-star in-house developers should be able to quickly spin up access to core IT infrastructure whenever they need it, while a third-party development contractor should only have limited access to those same resources for the time in which they are working in your environment–and no longer than that. 

    This is where we begin to see time-limited, credential-less secure access, enabled by ephemeral certificates, start to play a role in privileged access management. Ephemeral certificates are short-lived access tokens that are automatically generated and automatically expire–so access is granted only for as long as it is needed to authenticate and authorize privileged connections. 

    In other words, privileged access is able to move toward a just-in-time model, eliminating the need for passwords and clumsy credential management. IT users no longer need to authenticate using credentials at all–instead, based on predefined roles and security policies, they are granted access to resources only as and when required.

    Ultimately, ephemeral certificates help streamline access processes, ensuring that IT admins don’t have to worry about revoking access when access roles or needs change.

    Make It Easy on the IT Admin, Too

    Speaking of IT admins, it’s important to consider their experience, too.

    Admins want to give staff the best tools for the job without compromising corporate security. The friction between admins and developers begins when the developers feel that the tools admins force them to use are slowing down their work. In reaction, admins become frustrated when more unmanaged, unmonitored tools enter the corporate network, requiring more of their time to implement, configure or remediate if something has gone wrong.

    The right technology solutions make life easier for IT admins, too. That means secure access solutions that can be installed and deployed within a single day–not weeks–and that introduce automated routines and maintenance to eliminate manual work in the access management process. Accountability, in the form of session monitoring and logging, is also important. 

    Ultimately, it’s about giving IT admins some distance. They can retain the oversight they need to feel comfortable about organizational security, without needing to be on top of every single secure access decision in the organization. At the same time, developers retain the autonomy they need to work quickly without feeling like they’ve got someone looking over their shoulder. 

    By enabling rapid development, while keeping a watchful eye on enterprise security, enterprises can satisfy both their developers and IT admins, and ultimately, the business’s bottom line.

    — Markku Rossi

  • HashiCorp Terraform Enterprise Empowers IT Administrators

    HashiCorp Terraform Enterprise Empowers IT Administrators

    Most of what passes for management of IT infrastructure often amounts to little more than a Word document describing how a system is configured. HashiCorp developed Terraform to enable IT organizations to programmatically manage IT infrastructure. Now the company is taking that concept a step further with the release of Terraform Enterprise, a collaboration application that can be employed to programmatically manage IT infrastructure without requiring IT administrators to know how to program.

    HashiCorp co-CTO Armon Dadgar says Terraform provides an application that makes its Sentinel policy management framework more accessible. Previously, use of Terraform and Sentinel were limited largely to developers looking for a common way to manage infrastructure as code. But Dadgar says customer requests made it clear there was also demand for a collaboration application that did not require any programming skills to employ.

    Terraform Enterprise includes Workspaces, a set of modules that that can be delegated to separate teams. Dadgar says Workspaces are roughly equivalent to Git repositories that have access controls for each IT team, using a secure access markup language (SAML) that comes with built-in encryption.

    In addition, Terraform Enterprise exposes an application programming interface (API) that can be invoked for integration with existing tooling or application delivery pipelines. Dadgar says with the rise of multiple clouds in an organization, it’s now only a matter of time before existing approaches to managing IT infrastructure simple become obsolete. Pressure from developers to increase the amount of time it takes to provision and update IT infrastructure is only going to increase, says Dadgar.

    HashiCorp is effectively trying to smooth over one of the more contentious aspects of DevOps. In theory, developers want more control over IT infrastructure largely because they often view internal IT teams as being too slow. To enable IT organizations to be more responsive, various APIs have been exposed that can be invoked using IT automation framework. Many of those frameworks, however, require programming skills that most IT administrators don’t possess. Many organizations also don’t want developers to be managing IT infrastructure when they could be devoting that time to writing and test applications. Dadgar says Terraform Enterprise provides a graphical user interface (GUI) through which all the benefits of managing infrastructure as code can be attained without having to teach administrators how to program, or allowing programmers to invoke IT infrastructure resources without any adult supervision.

    HashiCorp is not the only provider of IT management frameworks trying to solve this issue. There are rival declarative frameworks for automating IT and many providers of the latest generation of software-defined infrastructure are embedding modern IT management frameworks within pre-integrated systems. But HashiCorp is one of the few vendors providing organizations with a dual approach using the same core underlying set of APIs. Rather than continuing to be at odds with one another, developers and IT administrators now could find it easier to collaborate using whatever approach to infrastructure as a code they best see fit.

    — Mike Vizard