Knowledge Article
Access Requests Milestone
Author
ryan_cutter
SailPoint
Access Requests are a critical component of identity management, allowing users to request the necessary permissions to perform their job functions effectively. Properly configuring access requests ensures that the right individuals have access to the right resources at the right time, enhancing both security and productivity. This guide provides detailed advice and identifies common pitfalls to help you configure, manage, and optimize your access request processes within your organization. Following these guidelines will help ensure a seamless and secure access request experience for all users.
1
Configure access request settings
Resources:
Identity Security Cloud
- Access Request Overview
- Access Request Best Practices
- MS Teams integration
- Slack integration
- Policies Overview
IdentityIQ
- Manage User Access
- Manage Access Request Guide
- QuickLink Menu
- MS Teams integration
- Temporary Access
- File Attachments for Access Requests
- Policies in IdentityIQ
Advice:
Create comprehensive access-request guidelines for both human and machine identities. Specify how requests are submitted, reviewed, and approved, and define who may request access to which resources; and on whose behalf. Establish roles, permissions, and policies to ensure requests are handled efficiently and securely.
Identify all systems, applications, data sources, and other resources that require access controls, and classify each by sensitivity.
Define access roles aligned to job functions. For every role, list the exact permissions required for each resource. For each access level, state the conditions under which access is granted (e.g., department needs, temporary assignments).
In every policy, include requirements for documenting the business justification and the approval workflow, and make the chain of accountability for each request explicit.
Pitfalls:
- Failing to properly define roles and permissions can lead to unauthorized access or hinder users from performing their job functions.
- Overly complex request settings can confuse users and delay the access request process.
- Creating a large of catalog of access request items and not using role assignments where applicable can cause confusion to end-users unsure of what items to request.
2
Confirm names and descriptions
Resources:
Identity Security Cloud
IdentityIQ
Advice:
Note: Only Identity Security Cloud and IdentityIQ customers with IdentityAI can leverage GenAI Entitlement Descriptions.
Continue to work with source owners to discover, analyze and set clear and business-friendly names and descriptions for all requestable access items. This helps users easily identify and request the correct access without needing to understand technical details.
Pitfalls:
- Using technical jargon or unclear names can lead to confusion and incorrect access requests.
- Inconsistent naming conventions can create difficulties in maintaining and updating access items.
3
Determine indirect provisioning process
Resources:
Identity Security Cloud
IdentityIQ
Advice:
Establish or integrate processes for indirect provisioning for sources/applications without direct connector/integration capabilities. This may involve creating workflows or utilizing middleware to facilitate provisioning tasks.
Pitfalls:
- Not having a clear process for indirect provisioning can result in delays and errors in access provisioning.
- Failing to document and communicate these processes can lead to confusion among IT staff and end-users.
4
Complete user acceptance testing
Advice:
Complete user acceptance testing with relevant stakeholders to ensure the access request system meets business requirements and functions as expected. Involve a diverse group of users to test different scenarios.
Pitfalls:
- Skipping or rushing through user acceptance testing can result in missed issues and a flawed access request system.
- Not involving a representative group of stakeholders can lead to unaddressed needs and unexpected problems after deployment.
5
Conduct end-user education
Resources:
Advice:
Educate end-users, requesters, approvers, and administrators on the access request process. Provide training sessions, documentation, and support resources to ensure everyone understands their roles and responsibilities.
Pitfalls:
- Insufficient training can lead to misuse of the access request system and security vulnerabilities.
- Failing to update training materials and resources as the system evolves can result in outdated information and confusion.