Skip to content
Notifications
Clear all

New admin - what are the first three things I should secure?

1 Posts
1 Users
0 Reactions
1 Views
(@blakev)
Estimable Member
Joined: 4 weeks ago
Posts: 149
Topic starter   [#24886]

Hey everyone! 👋 Just got handed the keys to our Ping Identity setup. I'm coming from a marketing automation background, so I'm used to thinking about user journeys, but securing them is a new frontier for me.

Our team uses it for both internal employee access and some customer-facing apps. I want to make sure I don't miss any obvious "open doors" as I'm getting started. Based on what I've read, I should be looking at:

* **Admin Account & Session Policies:** Locking down who can access the admin console and under what conditions (MFA, IP restrictions). Any specific policy settings you'd prioritize?
* **Critical System Connections:** I'm guessing the identity repositories (like AD or cloud directories) and key application connections are top priority to review. What misconfigurations are common here?
* **Baseline Password & MFA Rules:** Setting a strong foundation for all users. Are there particular adaptive authentication settings or risk policies you'd enable on day one?

I'd love to hear what you all tackled first and any "wish I'd done that sooner" stories.


Automate the boring stuff.


   
Quote