Securing File Access for a Global Dairy Exporter
Transforming file access management at scale for enhanced security and efficiency
Overview
A leading global dairy processor and exporter, operating in over 40 countries, faced growing risk and inefficiencies managing unstructured file data across its vast network. With increasing regulatory pressure and manual processes, the company sought an automated solution to secure sensitive folders and streamline data access for hundreds of business owners. Activate helped by automating and streamlining file access management, empowering business owners with clear control while ensuring security and compliance across their complex, global environment.
The Challenge
The customer needed to address significant issues with the structure, security and ongoing management of its shared folders, both secured and unsecured. Over time, shared folders had not been properly maintained, failing to keep pace with organisational changes such as mergers and acquisitions, restructures and physical site relocations.
As a result, the environment had become cluttered with outdated and poorly managed folders, many lacking clear ownership or appropriate access controls.
A key contributing factor was the absence of the right tools and processes to enable business units to manage their own departmental data. Additionally, users experienced poor service levels when requesting access to shared folders, due to inconsistent approval workflows and manual, inefficient provisioning processes.
The Solution
To address audit concerns and improve service levels for staff, the customer implemented Activate Folder Manager across its global infrastructure.
The solution enabled business users to request, approve and automatically manage access to secured shared folders across more than 95 file servers, without needing to log service desk tickets or involve IT in day-to-day access changes.
Key features that enabled this transformation included
- A user-friendly web interface that allowed staff to search for and request access to shared folders managed by Activate
- The ability to assign multiple business owners per secured folder, enabling them to govern access to their data. All access requests are logged and easily accessible for auditing
- Automated creation of new secured shared folders based on company policies, applying consistent naming conventions and ensuring appropriate Active Directory groups and business ownership are assigned
- Visibility into folder access through the Activate web portal, allowing business users to see exactly who has access to their departmental data
- Integration with Activate’s Role and Entitlements Module to automatically provision access to departmental folders during the onboarding process using role-based access controls.
Shared folders within the organisation were secured using Active Directory (AD) security groups.These groups grant users varying levels of access such as read-only or full write permissions. However, identifying which groups controlled which folders had become increasingly difficult due to dispersed and inconsistent access control lists (ACLs) throughout the file structure.
Activate Folder Manager centralised and simplified this information, allowing users to request access to shared folders without needing to know which security group managed them. Once a business owner approved a request, folder access was provisioned automatically, removing manual IT overhead.
In addition to streamlining access, Activate supported the customer in remediating legacy folder structures and broken security configurations through the following project tasks:
- Automated ownership discovery: Activate provided reporting and heuristics-based tools to help identify likely business owners based on folder usage patterns
- Custom Re-Secure Task: This tool automatically alerted affected users when folder permissions were updated, created new AD groups, applied them to folders and removed outdated or mis-configured groups. Legacy groups were relocated to a separate AD OU for review
- Move Folder Task: Automatically migrated folder structures to new locations, correcting permission inheritance issues in the process to ensure continued access for users
- Delete Folder Task: Cleaned up unused folders by removing all permissions except for a designated admin group, allowing for future recovery into a secure structure if required
- Legacy group migration: Activate ran a process to identify folders secured with outdated AD groups. Group members were emailed and asked to claim ownership. Upon confirmation, Activate automatically replaced legacy groups with standardised groups, migrated members and updated folder security.
By deploying Activate Folder Manager, the customer achieved a more secure, standardised and efficient approach to managing shared data, reducing risk, improving visibility and enabling business users with appropriate access control.
145,000+
Automated access changes per year.
~36,000
Support hours saved per year.
570,000+
Managed Secure Folders.
The Result
The implementation of Activate’s File and Folder Manager delivered measurable improvements across the organisation. By adopting Activate’s File and Folder Manager, the global dairy processor and exporter streamlined and secured its sensitive file access processes. The solution improved accuracy, accelerated response times and gave the business greater control over their departmental data. It also enabled amore robust, automated approach to managing shared folders, reducing manual overhead and supporting better collaboration organisation-wide.
Key Outcomes
- Lower operational costs through self-service shared folder management
- Significant reduction in service desk tickets and calls
- Improved service levels through automation of complex access processes
- Strengthened security, auditing and compliance around folder access
- Consistent creation of secured folders aligned with naming conventions and standardised permissions
- Reduced service desk workload by enabling business owners to manage access directly
- Empowered business owners to add or remove users without needing IT tools or logging support requests.