Solution
Post-merger network consolidation
An acquisition just doubled your device estate and nobody trusts the other network.
What is going on
Two networks with two sets of assumptions about who belongs, two directories, and no shared basis for trusting a device from the other side. The pressure is to connect them quickly, which is exactly how one environment's weakness becomes both environments'.
What this is designed to achieve
A single access control model spanning both estates, with a staged path to a common policy rather than a flat interconnect.
It starts with
Discovery across both estates and a comparison of what each currently trusts and why.
The phases it runs through
- Phase 1
Discover
What is actually on the network?
- Phase 2
Design
What should be allowed, and who decides?
- Phase 3
Prove
What would have happened if this were enforcing?
- Phase 4
Enforce
Can we turn this on without an outage?