Blog
New capability announcement! Direct entitlement assignment for roles
Author
PGookin
SailPoint
We are excited to announce the upcoming general availability release of direct entitlement assignment for roles. This release enhances the Identity Security Cloud access model with the ability to assign entitlements directly to roles. Prior to this release, entitlements could only be added to roles by including them in an access profile. With this release, you will be able to add individual entitlements, access profiles, or both to your Identity Security Cloud and IdentityNow roles. This provides a much more flexible approach which allows Identity Security Cloud and IdentityNow customers to more easily design and implement an access model that aligns with your business requirements.
This feature:
- Allows you to assign entitlements directly to roles so that when users are assigned to a role, they will automatically be given the role's entitlements AND when users are removed from a role the entitlements will be automatically removed.
- Reduces "Access Profile sprawl" by eliminating the need to create one-to-one access profile to entitlement configurations.
- Maintains the ability to assign Access Profiles to roles.
- Improves the admin user experience including robust search, sort, and filtering options to allow role and role sub-admins to easily assign, maintain, and remove role assignments for both access profiles and entitlements.
- Provides updated search and certification user experiences to support direct entitlement assignments.
Release schedule:
- Staging tenant enablement will begin on January 22nd
- Production tenant enablement will begin on January 29th and is expected to be fully complete by February 8th.
We are pleased to be delivering this very important and highly anticipated capability, and look forward to your continued feedback.