After eliminating AD FS as an option, the company evaluated several IDaaS solutions and selected CyberArk Identity based on product functionality, the ability to easily integrate cloud apps, MDM features for mobile devices, and company reputation. To meet disaster recovery requirements, SBA Communications first looked at creating an additional AD FS environment. They took into consideration hardware and licensing costs, the cost of more co-location space, additional consulting expenses, and internal resource requirements for maintenance and management. Because SBA Communications was now running two versions of AD FS, to ensure uptime they would either need to finally migrate all the cloud apps on the old AD FS system to the new one, or they’d need to build out two separate additional environments, which would double the costs. Not migrating was cost prohibitive and migration wasn’t a real option either. The integration process was extremely difficult with AD FS. Each new cloud app seemed to present a unique situation. Some apps took ten weeks to integrate, and sometimes entire development initiatives were required. Doing that all over again wasn’t an option for them. The ROI on the entire initiative just wasn’t there. SBA Communications decided to look at IDaaS (Identity-as-a-Service) solutions that could solve the problem and minimize management and maintenance overhead. After a preliminary evaluation, the company narrowed their choice down to two providers. In the end, it wasn’t just about dollars. It came down to product functionality and which provider would best support them in integrating new apps. Company reputation, customer interviews, and existing integrations with SaaS providers also played a significant role. MDM (Mobile Device Management) capabilities were the icing on the cake. Simultaneous to addressing its AD FS problem, SBA was also in the process of evaluating Cisco’s Meraki MDM solution for management of mobile devices. They needed an MDM solution to ensure that they could enforce passwords on devices, that mobile communication would be encrypted, and that they could eliminate proprietary SBA Communications email from any mobile device at a moment’s notice. They needed to accomplish all that without damaging the device or deleting personal information. And last, they needed control and reporting on all mobile devices connecting to their servers. Because those capabilities are inherent to CyberArk Identity, they realized they wouldn’t even need a separate MDM solution.
Read More