Management of application access to directories by a hosted directory service
Abstract
Features are disclosed for facilitating management of network directories of multiple organizations by a directory management system. Various applications can access the directories of the organizations via the directory management system according to the permissions that the applications have been granted by the respective organizations. Organizations may maintain directories on-premises or off-premises, and the applications can access the directories via the directory management system regardless of the physical location of the directories. Additionally, the applications may be hosted by a computing service provider that also hosts or otherwise manages the directory management service, or the applications can be hosted by third-party servers separate from the directory management system and the organizations.
Claims
exact text as granted — not AI-modifiedWhat is claimed is:
1 . A directory management system comprising one or more physical computing devices programmed with executable instructions to implement a process comprising:
receiving directory access configuration information for a directory, the directory access configuration information including application access policy information for accessing the directory; determining, for a first application, based on the received access configuration information, a first policy regarding accessing the directory; responding to a request from the first application to perform a first action on the directory by determining, based on the first policy, whether the first action is authorized, and when the first action is authorized, by performing the first action on the directory on behalf of the first application; determining, for a second application, based on the received access configuration information, a second policy regarding accessing the directory, wherein the second policy is different than the first policy; and responding to a request from the second application to perform a second action on the directory by determining, based on the second policy, whether the second action is authorized, and when the second action is authorized, by performing the second action on the directory on behalf of the second application.
2 . The system of claim 1 , wherein the directory management system comprises a directory management user interface that includes functionality for a provider of the directory to separately specify, for at least the first and second applications, permissions for accessing the directory.
3 . The system of claim 1 , wherein the directory is hosted remotely from the directory management system, and the access configuration information includes a network address of the directory.
4 . The system of claim 3 , wherein the access configuration information additionally includes user account information, the user account information including permissions that specify actions the directory management system is authorized to perform on the directory on behalf of applications.
5 . The system of claim 4 , wherein the directory management system is configured to determine whether the first action is authorized based on said permissions and based additionally on the first policy.
6 . The system of claim 3 , wherein the directory management system performs the first and second actions on the directory using a user account created for the directory management system.
7 . The system of claim 1 , wherein the directory management system receives said requests from the first and second applications via an application programming interface of the directory management system.
8 . The system of claim 1 , wherein each of the first and second actions modifies contents of the directory.
9 . The system of claim 1 , wherein the directory management system controls access by at least the first and second applications to each of a plurality of directories of each of a plurality of respective organizations, and includes a directory management user interface that enables each organization to separately specify, for at least the first and second applications, operations that can be performed by the first and second applications on a directory of the respective organization.
10 . A computing system that hosts a directory management service, the computing system comprising one or more computing devices and being programmed to provide at least:
a directory management user interface that includes functionality for an owner of a directory to separately specify, for each of a plurality of applications, permissions of the applications to perform operations on the directory, including operations that modify contents of the directory; and a data repository that stores application access data for each of a plurality of directories of each of a plurality of organizations, said application access data specified by the organizations for their respective directories via the directory management user interface; wherein the computing system is programmed to respond to a request from an application to perform on operation on a first directory of a first organization by using at least the application access data of the organization to determine whether the operation is authorized, and when the operation is authorized, by performing the operation on the first directory on behalf of the application, said operation modifying contents of the first directory.
11 . The computing system of claim 10 , wherein the first directory is hosted externally to the computing system.
12 . The computing system of claim 10 , wherein the application is hosted externally to the computing system, and makes the request using an application programming interface of the directory management service.
13 . The computing system of claim 10 , wherein the computing system is programmed to perform the operation on the first directory using a user account that includes permissions that specify actions the directory management service is authorized to perform on the first directory on behalf of applications.
14 . The computing system of claim 10 , wherein the computing system is programmed to determine whether the operation is authorized based additionally on access rights of a user that invokes the first application.
15 . The computing system of claim 10 , wherein the first directory comprises a collection of data regarding a plurality of resources of a computing network of the first organization, and at least a portion of the data is organized into objects representing individual resources of the plurality of resources.
16 . A method of controlling access by applications to a directory of an organization, the method comprising, by a computing system that hosts a directory management service:
receiving directory access configuration information for a directory of an organization, the directory access configuration information submitted via a user interface of the directory management service, the directory access information separately specifying, for each of a plurality of applications, permissions for performing operations on the directory; receiving, from a first application of the plurality of applications, a request to perform on operation on the directory of the organization, the operation comprising a modification to contents of the directory; in response to the request, determining, based at least in part on said permissions, whether the operation is authorized; and in response to determining that the operation is authorized, performing the operation on the directory on behalf of the first application.
17 . The method of claim 16 , wherein the directory is hosted externally to the computing system.
18 . The method of claim 16 , wherein the first application is hosted externally to the computing system, and the request is submitted to the computing system via an application programming interface of the directory management service.
19 . The method of claim 16 , wherein the determination of whether the operation is authorized is based additionally on access rights of a user that invokes the first application
20 . The method of claim 16 , wherein performing the operation on the directory on behalf of the first application comprises using a user account to perform the operation, the user account assigned to the directory management service by the organizationJoin the waitlist — get patent alerts
Track US2018198829A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.