Skip to content
Clumio

RBAC vs EBAC for Data Compliance: Clumio Insights

Explore the key differences between Role-Based Access Control (RBAC) and Entity-Based Access Control (EBAC) in the context of data compliance


Today, as Enterprise Administrative teams are being asked to do more with less, the push for self-service has never been greater. Off-loading mundane tasks like user requested backups and file restores frees up time on the Core IT team to focus on more mission critical tasks. However, granting access to these powerful tools which house your company’s most critical data should be tightly controlled in order to meet data compliance needs and prevent any unintentional or malicious consequences.

So how do you give access to users to perform these valid functions but prevent any unintended or harmful consequences? Simple, a combination of RBAC and EBAC enables you to provide user access that conforms to your organization’s data compliance requirements.

Che cos’è l’RBAC e come si usa?

Role Based Access Control or RBAC has been around forever, and administrators are very familiar with the concept. At its simplest form specific users can be given Read-Only, Write, or Read/Write access. In the old days of simple file shares, this satisfied most people’s needs. However, in today’s enterprise world we need much more fine tuned granularity.

I tempi in cui si assegnavano privilegi di superamministratore a tutti sono ormai lontani. Solo pochi utenti selezionati dovrebbero disporre di questi privilegi “divini”, che dovrebbero essere sottoposti a un rigoroso monitoraggio e a controlli accurati. D’altra parte, l’accesso in sola lettura può risultare troppo restrittivo e impedire agli utenti di svolgere le attività necessarie, costringendoli a aprire ticket presso il team IT. Deve essere possibile trovare un giusto compromesso.

At Clumio, we give administrators the ability to give their end-users specific predefined roles that would more closely align with their job function without being too open or restrictive. At a glance, the below list of roles should fit 99% of permission levels administrators wish to give their users without “giving away the keys to the castle.”

Inoltre, ogni ruolo dispone di controlli molto dettagliati.

Che cos’è l’EBAC e come si usa

Il controllo degli accessi basato sulle entità (EBAC) è un concetto relativamente recente che consente di definire dei limiti attorno a risorse specifiche e di raggrupparle per controllare in modo più preciso a cosa possono accedere gli utenti. Questo approccio si rivela particolarmente efficace per le grandi aziende e persino per gli MSP (Managed Services Providers), poiché offre un supporto più efficace per garantire un’esperienza di self-service più completa per le richieste di base degli utenti.

Clumio’s approach to EBAC introduces the concept of an Organizational Unit or OU. Administrators can create these OUs and then place specific users and resources inside of these OUs to create isolation, restrict outside access, and reduce the blast radius in the event of unauthorized access. Let’s take a real world example to demonstrate how RBAC and EBAC function together to deliver a simple yet powerful mechanism to manage data access.

Come funzionano RBAC ed EBAC in Cohesion

In the below diagram we have created 3 different OUs – AWS Team, VMC Team and M365 Team. Inside each of these OUs are specific resources such as AWS accounts, VMware Cloud on AWS SDDC’s, and M365 Domains.

For example: When the user Dennis logs in, he can only see resources in the OU that he belongs to which are the two M365 domains. Dennis is an OU admin so he has full control over everything inside his M365 Team OU, but he has no access or visibility into the VMC Team or AWS Team’s OUs.

D’altra parte, Jim lavora all’Helpdesk e il suo account utente è presente in tutte e tre le unità organizzative (OU). Quando Jim effettua l’accesso, ha visibilità sulle risorse all’interno di tutte e tre le OU, ma le sue autorizzazioni limitate relative all’Helpdesk gli consentono solo di svolgere funzioni specifiche all’interno di ciascuna delle OU di cui fa parte.

In summary, RBAC controls what you can do and EBAC controls what you can see. By combining these two control methods, you can safely grant access to powerful enterprise tools such as Clumio and conform to your data compliance needs.

Guarda questa demo per scoprire come impostare rapidamente i controlli di accesso in Clumio.

 

More related posts


Thumbnail_Blog-Dangerous-Silos-IDC-Resops-2026 (1)

The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan

Read more about The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan
Thumbnail_Blog-IDC-Resops-2026

Business Continuity Planning for the Cloud-Native Era

Read more about Business Continuity Planning for the Cloud-Native Era
Thumbnail_Blog-Bringing-Trust-to-CVE-2026

Demystifying SOC 2 Data Protection Requirements

Read more about Demystifying SOC 2 Data Protection Requirements