Skip to main content

Role-Based Access Control (RBAC)

Applies to:
Zero TrustAccess PoliciesAzure AD GroupsGeographic Restrictions

What is Access Control Policy?​

The Access Control Policy for DuoKey DKE is designed to provide organizations with the ability to control and restrict the use of encryption keys based on predefined roles and attributes. This feature is pivotal for organizations seeking to implement stringent security measures to protect sensitive information from unauthorized access.

Supported Access Control Policies

User Restriction

Allow or block specific UPNs

Device Restriction

Control access by source IP

Geographic Restriction

Limit by geographic location

Group Management

Azure AD group integration

Core Principles of Zero Trust​

Zero Trust is a security model that requires strict identity verification for every person and device trying to access resources on a private network, regardless of whether they are sitting within or outside of the network perimeter.

DuoKey DKE integrates this model by ensuring:

  • No implicit trust is granted to assets or user accounts based solely on their physical or network location
  • Authentication and authorization (both subject and device) are discrete functions performed before a session to an enterprise resource is established

Architecture and Components​

ComponentDescription
DKE Console (Cockpit)Central hub for configuring and managing access control policies
DKE Web Service APIInterfaces with Microsoft environments to manage encryption/decryption
Policy EnforcerValidates access requests against configured policies
DKE Cryptographic ServiceSecure generation and storage of DKE keys in MPC

Policy Enforcement​

The policy engine (ABAC) defines who can access what resources, under which conditions. These policies are stored in a flexible and maintainable format, making it easy to update rules as organizational needs evolve.

The engine evaluates the context of each access request, such as the user's location, the device state, and membership in specific Azure AD groups, to make real-time decisions about whether to allow access to a decryption key.

Secure Content Key Decryption​

When a user attempts to access an encrypted document in Office 365, DKE 365 intercepts this request to determine if the user should be granted access.

The access control engine consults the defined policy, evaluates the user's context, and either permits or denies the decryption key based on the policy's criteria.

Security Targets​

Prevention

Prevent unauthorized users and devices from accessing sensitive encrypted data

Compliance

Support compliance with data protection laws by ensuring access controls meet standards

Data Security

Protect sensitive information from data breaches with authorized-only decryption

Threat Mitigation​

AssetThreatMitigation Strategy
Encryption KeysUnauthorized AccessGranular access controls based on roles, IP, location, and group membership
Encryption KeysInsider ThreatsRBAC and strict policy enforcement to limit access based on necessity
User DataSpoofing IdentityRobust authentication and dynamic policy enforcement based on JWT claims
User DataData ExfiltrationData encrypted at all times; keys managed in MPC with strict policies
Access PoliciesPolicy TamperingAudit trails and logging; regular policy reviews
System IntegrityDenial of ServiceRedundancy, failover, rate limiting, and monitoring

Configure RBAC​

Create RBAC Policy​

1

Log in to DuoKey Cockpit

2

Open Access Control Policy

In the Administration Tab, open DuoKey - DKE: Access Control Policy

3

Create New Policy

  1. Click Create New Access Policy
  2. Enter Conditional Access Policy name
  3. Select an Action → Allow
  4. Select the Organisation Unit
4

Configure Policy Rules

Choose what type of access policy needs to be applied by selecting the different tabs and filling the mandatory fields.

Actions​

Allow​

The following example lets any user with a given email address and UPN reach the application:

ActionRule TypeSelectorValue
AllowAny Of[email protected]

Block​

For example, this configuration blocks every request to the application that tries to log in with the IP Address from Brazil, except those from Australia:

ActionRule TypeDeviceValue
BlockInclude (IP Only)IP OnlyBrazil: 101.33.22.0
BlockExclude (IP Only)IP OnlyAustralia: 1.178.144.0

Bypass​

The Bypass action allows all access requests and will not verify any policy rule.

Policy Configuration Tabs​

Apply RBAC Policy to DKE Web Service​

1

Open Apps Tab

Navigate to DuoKey - Apps

2

Select App

Select the App you wish to enforce the newly generated RBAC Policy

3

Edit App

Click Actions → Edit

4

Navigate to Access Control

Click Next three times until you see Your DKE Access control policy

5

Select Policy

Select your RBAC-Policy

6

Finish Wizard

Complete the DKE-App Wizard

Note

The RBAC Policy is immediately applied to DKE-Decrypt Requests when submitting the configuration.