MPLS alternative
-
@scottalanmiller said in MPLS alternative:
The need for user management at the OS level primarily comes from LAN-based design. Not 100%, but maybe 85%. Once you are LANless / Zero Trust, the need to control the users at the device level changes dramatically. There are good reasons to still want it, but it has to become a business need, not a "nice if all other things were equal." It comes at high cost and carries risks, so you have to have a value that supersedes those values to justify it.
I completely agree - though I assume that the company will want people to not use local admin accounts - or is that even over reaching?
-
@Dashrender said in MPLS alternative:
@scottalanmiller said in MPLS alternative:
@Dashrender said in MPLS alternative:
what would you do for a management solution for 300+ users on company owned equipment?
It's not that easy to say what TO do. That requires a lot of research. But knowing what NOT to do is a lot simpler. AD is absolutely not a good solution for a lot of sites. Even Microsoft hasn't recommended that in a long time. That's why they moved to Azure AD internally as their product for that long ago.
We have no reason to believe that they even need user management, there's no way to have that assumption. I've worked in companies that size that saw zero value to having that and I see that play out time and time again. The need for user management on the OS is probably around 50/50.
So without even knowing if the need user management, it's impossible to even start to guess how best to approach it.
Don't limit this to just user management - what about device management?
Those are very different things. AD is a user management system, but has no device management. So that's created a totally different discussion. Most people with AD use local device management via GPO. AD does a good job of making people think that GPO is centralized, but it is not. The info is centralized, but the management is done locally via a GPO agent on the Windows boxes.
-
@scottalanmiller said in MPLS alternative:
What's doing it today? Not the MPLS, because that has zero security. So what's doing it now for you?
We log into citrix workspace with our AD credentials
-
@Dashrender said in MPLS alternative:
@scottalanmiller said in MPLS alternative:
The need for user management at the OS level primarily comes from LAN-based design. Not 100%, but maybe 85%. Once you are LANless / Zero Trust, the need to control the users at the device level changes dramatically. There are good reasons to still want it, but it has to become a business need, not a "nice if all other things were equal." It comes at high cost and carries risks, so you have to have a value that supersedes those values to justify it.
I completely agree - though I assume that the company will want people to not use local admin accounts - or is that even over reaching?
Why would they care? Can someone care? of course. There are good cases for caring. There are good cases for not caring. In a LANless world, you don't necessarily care very often because you aren't in the business of trying to centrally control the device. But that doesn't mean you can't, or even shouldn't, but it's purely an option.
-
@hobbit666 said in MPLS alternative:
@scottalanmiller said in MPLS alternative:
What's doing it today? Not the MPLS, because that has zero security. So what's doing it now for you?
We log into citrix workspace with our AD credentials
So you already have a dangerous attack vector exposed across the MPLS today. But so there are two steps here....
- How to make XenApp LANless and the answer is "it already is."
- How to secure it given that it has a major security flaw in how it is tied to AD?
There are lots of ways to do number 2. And one of the answers can be VPN, but VPN meaning something wholly different from how you are using it with MPLS. It's using VPN as a 2FA tool, rather than as an encryption or LAN connection tool. This is the standard that most people do, because it's easy to understand and managers like hearing "VPN" because they don't get it. But this is the pattern "everyone" uses to secure XenApp, but it's nothing like what we were talking about with VPN for site to site connections. It's client to client connection from an end point directly to the XenApp server or farm.
-
@scottalanmiller said in MPLS alternative:
@hobbit666 said in MPLS alternative:
Those i get, but what about printing to office printers.....
So printing is a weird one. Typically printing desires physical proximity and no security. The nature of printing is insecure. Do you really need printing security? And do you really need to print from one site to another instead of printing locally? These things are possible, just really rare.
Printing does have options to use some LANless design, but typically we ignore this here as we are talking about a peripheral device that simply "doesn't matter" enough.
So I guess the real question is... since you can "just print" without any discussion or design whatsoever, what's the actual problem that you are trying to solve? I'm not sure what the question is. Whether you have LANbased or LANless design, if you hook up a USB printer you just print, if you hook up a network printer, you just print. They really fall outside of this discussion unless there is some extra factor that we can't anticipate.
We know they are old school setup - so we assume they are using Windows print queues to print (man I hope they are all local to each subnet and not flowing over the MPLS). with that type of thinking comes these questions.
I agree - assuming insecure printing is OK - then just move to direct IP/network based printing or USB based printing. problem solved.
-
@scottalanmiller said in MPLS alternative:
@hobbit666 said in MPLS alternative:
or accessing the Citrix farm
So this is already LANless, and requires no MPLS or VPN already. This only seems complex because it's already been made complex. But if you just deploy Citrix XenApp, it "just works". It's already functional with nothing more needed.
I know, because we do this here. This is another "it works by default", you have to break its default to have the issue.
Sure - but where does it's users come from? that server farm surely doesn't want to manage 300+ accounts across 15 machines...
-
@hobbit666 said in MPLS alternative:
@scottalanmiller said in MPLS alternative:
What's doing it today? Not the MPLS, because that has zero security. So what's doing it now for you?
We log into citrix workspace with our AD credentials
Citrix themselves make a VPN alternative specifically for this. RedGate (I think) makes one for Microsoft RDP. AppGate makes a third party one for Citrix. There are lots of solutions to this that aren't VPNs. And loads upon loads of solutions that use VPNs as part of the mechanism.
I think CloudFlare Teams does this, too.
And all of that is to deal with legacy AD. Remove legacy AD and everything totally changes. If you use Okta instead, for example, I doubt any of that complexity is needed. The issue is using a LANbased system, then trying to figure out how to be LANless with one piece, but not the big piece, while staying tied together.
-
@scottalanmiller said in MPLS alternative:
@Dashrender said in MPLS alternative:
@scottalanmiller said in MPLS alternative:
The need for user management at the OS level primarily comes from LAN-based design. Not 100%, but maybe 85%. Once you are LANless / Zero Trust, the need to control the users at the device level changes dramatically. There are good reasons to still want it, but it has to become a business need, not a "nice if all other things were equal." It comes at high cost and carries risks, so you have to have a value that supersedes those values to justify it.
I completely agree - though I assume that the company will want people to not use local admin accounts - or is that even over reaching?
Why would they care? Can someone care? of course. There are good cases for caring. There are good cases for not caring. In a LANless world, you don't necessarily care very often because you aren't in the business of trying to centrally control the device. But that doesn't mean you can't, or even shouldn't, but it's purely an option.
malware gets onto the device because they have local admin - (more easily at least) and that malware takes over their LANless products - like OD4B... you don't think that's worth not running as admin for most?
-
@Dashrender said in MPLS alternative:
@scottalanmiller said in MPLS alternative:
@hobbit666 said in MPLS alternative:
or accessing the Citrix farm
So this is already LANless, and requires no MPLS or VPN already. This only seems complex because it's already been made complex. But if you just deploy Citrix XenApp, it "just works". It's already functional with nothing more needed.
I know, because we do this here. This is another "it works by default", you have to break its default to have the issue.
Sure - but where does it's users come from? that server farm surely doesn't want to manage 300+ accounts across 15 machines...
Right, why manage them? The simple answer is... just don't. Managing accounts isn't actually something most companies need. It feels that way because we've always done it. But mostly, that's because of good marketing, not because it was actually a necessity. But the need for it has plummeted as well. In 2001, it made a lot more sense than it does in 2021.
-
@Dashrender said in MPLS alternative:
@scottalanmiller said in MPLS alternative:
@Dashrender said in MPLS alternative:
@scottalanmiller said in MPLS alternative:
The need for user management at the OS level primarily comes from LAN-based design. Not 100%, but maybe 85%. Once you are LANless / Zero Trust, the need to control the users at the device level changes dramatically. There are good reasons to still want it, but it has to become a business need, not a "nice if all other things were equal." It comes at high cost and carries risks, so you have to have a value that supersedes those values to justify it.
I completely agree - though I assume that the company will want people to not use local admin accounts - or is that even over reaching?
Why would they care? Can someone care? of course. There are good cases for caring. There are good cases for not caring. In a LANless world, you don't necessarily care very often because you aren't in the business of trying to centrally control the device. But that doesn't mean you can't, or even shouldn't, but it's purely an option.
malware gets onto the device because they have local admin - (more easily at least) and that malware takes over their LANless products - like OD4B... you don't think that's worth not running as admin for most?
Running as admin and giving admin access are two unrelated topics. You are leaping from one thing of who is in control to the person being in control will violate basic computing policies and HR won't do anything about it. You can't assume, in trying to design a good business, that all parts of the business other than the isolated piece we are looking at, will simply fail and be allowed to fail. That's illogical and contrived.
But, then you always have to ask, why are you using products that that malware can take over? Why that exposure?
-
@scottalanmiller said in MPLS alternative:
@Dashrender said in MPLS alternative:
@scottalanmiller said in MPLS alternative:
@hobbit666 said in MPLS alternative:
or accessing the Citrix farm
So this is already LANless, and requires no MPLS or VPN already. This only seems complex because it's already been made complex. But if you just deploy Citrix XenApp, it "just works". It's already functional with nothing more needed.
I know, because we do this here. This is another "it works by default", you have to break its default to have the issue.
Sure - but where does it's users come from? that server farm surely doesn't want to manage 300+ accounts across 15 machines...
Right, why manage them? The simple answer is... just don't. Managing accounts isn't actually something most companies need. It feels that way because we've always done it. But mostly, that's because of good marketing, not because it was actually a necessity. But the need for it has plummeted as well. In 2001, it made a lot more sense than it does in 2021.
You've completely lost me -
You SAM are standing up a Citrix farm of 15 servers for 300+ users - where does their logon information come from so those 300+ users can log into the Citrix app?
I think that's as simple a question as I can get.
-
@scottalanmiller said in MPLS alternative:
@Dashrender said in MPLS alternative:
@scottalanmiller said in MPLS alternative:
@Dashrender said in MPLS alternative:
@scottalanmiller said in MPLS alternative:
The need for user management at the OS level primarily comes from LAN-based design. Not 100%, but maybe 85%. Once you are LANless / Zero Trust, the need to control the users at the device level changes dramatically. There are good reasons to still want it, but it has to become a business need, not a "nice if all other things were equal." It comes at high cost and carries risks, so you have to have a value that supersedes those values to justify it.
I completely agree - though I assume that the company will want people to not use local admin accounts - or is that even over reaching?
Why would they care? Can someone care? of course. There are good cases for caring. There are good cases for not caring. In a LANless world, you don't necessarily care very often because you aren't in the business of trying to centrally control the device. But that doesn't mean you can't, or even shouldn't, but it's purely an option.
malware gets onto the device because they have local admin - (more easily at least) and that malware takes over their LANless products - like OD4B... you don't think that's worth not running as admin for most?
Running as admin and giving admin access are two unrelated topics. You are leaping from one thing of who is in control to the person being in control will violate basic computing policies and HR won't do anything about it. You can't assume, in trying to design a good business, that all parts of the business other than the isolated piece we are looking at, will simply fail and be allowed to fail. That's illogical and contrived.
But, then you always have to ask, why are you using products that that malware can take over? Why that exposure?
WHAT? Are you implying that a company simply "would" have policies that users not run as local admins? Ok, honestly hadn't considered that. But that said - that will almost NEVER happen unless the company sets up the computer for the user, and creates the user's local account as a non admin for them. then the installer can decide wither or not to provide the local admin password to the user a well for when that's needed.
If I simply gave my users a brand new Windows machine - they would NEVER use any account other than the very first one that gets setup upon first boot, which by default is a local admin. This is the bit you have to get past in my mind.
As for your question on malware take over - really? So NC - you refuse to use local sync? - and targeted malware could still be on the machine and use the web browser to attack using the user's logon if the attacker wants to push it hard enough.... yeah, I know, that's a bit over the top though.
-
@Dashrender said in MPLS alternative:
@scottalanmiller said in MPLS alternative:
@Dashrender said in MPLS alternative:
@scottalanmiller said in MPLS alternative:
@hobbit666 said in MPLS alternative:
or accessing the Citrix farm
So this is already LANless, and requires no MPLS or VPN already. This only seems complex because it's already been made complex. But if you just deploy Citrix XenApp, it "just works". It's already functional with nothing more needed.
I know, because we do this here. This is another "it works by default", you have to break its default to have the issue.
Sure - but where does it's users come from? that server farm surely doesn't want to manage 300+ accounts across 15 machines...
Right, why manage them? The simple answer is... just don't. Managing accounts isn't actually something most companies need. It feels that way because we've always done it. But mostly, that's because of good marketing, not because it was actually a necessity. But the need for it has plummeted as well. In 2001, it made a lot more sense than it does in 2021.
You've completely lost me -
You SAM are standing up a Citrix farm of 15 servers for 300+ users - where does their logon information come from so those 300+ users can log into the Citrix app?
I think that's as simple a question as I can get.
Oh, specifically for Citrix. So in that case, I don't know what ALL options Citrix provides. In the case of RDS you are forced to use AD, but it can be "local AD" without any network connection. There is a LANless way to use AD for that.
But for our RDP farm, we use local users. Easier to do local than to do AD (by the tiniest amount.)
-
@Dashrender said in MPLS alternative:
WHAT? Are you implying that a company simply "would" have policies that users not run as local admins? Ok, honestly hadn't considered that. But that said - that will almost NEVER happen unless the company sets up the computer for the user, and creates the user's local account as a non admin for them. then the installer can decide wither or not to provide the local admin password to the user a well for when that's needed.
Setting up the computer initially (imaging it, for example) is different than having a big user management system for once they hand out the machines.
Also, pick a good OS and this problem solves itself Only Windows shops can even end up having this discussion! And Windows is often an artifact of LAN thinking. Again, not always, but often.
But by default, the Linux, Mac, and ChromeOS worlds have this solved right out of the gate.
-
@Dashrender said in MPLS alternative:
If I simply gave my users a brand new Windows machine - they would NEVER use any account other than the very first one that gets setup upon first boot, which by default is a local admin. This is the bit you have to get past in my mind.
Sure, so don't do that. That's, again, a different failure. You are assuming bad imaging or setup or handover, then using that as the basis for needing all this complication after the fact. Solve the problem at the root, rather than applying bandaids later.
-
@scottalanmiller said in MPLS alternative:
@Dashrender said in MPLS alternative:
@scottalanmiller said in MPLS alternative:
@Dashrender said in MPLS alternative:
@scottalanmiller said in MPLS alternative:
@hobbit666 said in MPLS alternative:
or accessing the Citrix farm
So this is already LANless, and requires no MPLS or VPN already. This only seems complex because it's already been made complex. But if you just deploy Citrix XenApp, it "just works". It's already functional with nothing more needed.
I know, because we do this here. This is another "it works by default", you have to break its default to have the issue.
Sure - but where does it's users come from? that server farm surely doesn't want to manage 300+ accounts across 15 machines...
Right, why manage them? The simple answer is... just don't. Managing accounts isn't actually something most companies need. It feels that way because we've always done it. But mostly, that's because of good marketing, not because it was actually a necessity. But the need for it has plummeted as well. In 2001, it made a lot more sense than it does in 2021.
You've completely lost me -
You SAM are standing up a Citrix farm of 15 servers for 300+ users - where does their logon information come from so those 300+ users can log into the Citrix app?
I think that's as simple a question as I can get.
Oh, specifically for Citrix. So in that case, I don't know what ALL options Citrix provides. In the case of RDS you are forced to use AD, but it can be "local AD" without any network connection. There is a LANless way to use AD for that.
But for our RDP farm, we use local users. Easier to do local than to do AD (by the tiniest amount.)
yeah to endpoints I could see the local bit - but that's really only for the user of the device - which is fine.
What is "Local AD"? how does that span the 15 servers in the Citrix Farm?
I just found an article that seems to talk about using AAD, but then it clearly starts out by saying
the use of an Active Directory domain continues to remain a requirement.
-
@scottalanmiller said in MPLS alternative:
@Dashrender said in MPLS alternative:
If I simply gave my users a brand new Windows machine - they would NEVER use any account other than the very first one that gets setup upon first boot, which by default is a local admin. This is the bit you have to get past in my mind.
Sure, so don't do that. That's, again, a different failure. You are assuming bad imaging or setup or handover, then using that as the basis for needing all this complication after the fact. Solve the problem at the root, rather than applying bandaids later.
No I wasn't assuming that - but I did want you to get MORE specific, which you seem to keep avoiding.
-
@Dashrender said in MPLS alternative:
As for your question on malware take over - really? So NC - you refuse to use local sync? - and targeted malware could still be on the machine and use the web browser to attack using the user's logon if the attacker wants to push it hard enough.... yeah, I know, that's a bit over the top though.
So NC, we don't use local sync, that's correct. We only use NC for giant files and that would be a problem if we synced them. Not sure how targeted malware would do what you are saying, but theoretically anything is a vector.
Not that people shouldn't use NC with local sync, it's a valid use case. Just we don't. No need.
We go farther than most companies to LANless. Zero Trust is more the security aspect of LANless. We also do fileless. Not 100%, but we are getting there. We use essentially no files any longer.
-
@Dashrender said in MPLS alternative:
What is "Local AD"? how does that span the 15 servers in the Citrix Farm?
AD DCs running in and only in, the cluster. This is a common pattern, actually, at least with RDS (which is the basis for XenApp). We do this for customers all the time. AD that's dedicated to the RDS/XA and isn't on the LAN itself.