Knowledge Article

Best Practices: Configuring External Access Requests with IdentityNow

Author

  • neil_mcglennon

    SailPoint

Overview


IdentityNow is a flexible platform which offers many implementation choices when it comes to access request. Besides, IdentityNow's easy-to-use access request interface, access requests can also be initiated in external solutions as well. A good example of this is the ServiceNow Service Catalog integration with IdentityNow. However we're not just limited to ServiceNow. Pretty much any other external system can be integrated with IdentityNow's access request REST APIs, allowing access requests to flow from an external system into IdentityNow for provisioning fulfillment.

When setting up your external system for access request with IdentityNow, there are some best practices you might want to consider. This document goes over some of those special considerations for your implementation.

Approval Considerations


When doing any sort of externalized access request integration, it is good to identify where approvals might take place. Approvals could take place on the external access request before IdentityNow is involved, and approvals could also take place within IdentityNow itself. The approvals are up to your IdentityNow configuration and what capabilities your external access request system might have. Regardless of where, SailPoint recommends having two approvals on any access, per audit guidelines.

If your external access request solution does allow for approvals, it might be tempting to do approvals there and forgo access approvals in IdentityNow. This would mean that IdentityNow's accesses (roles, access profiles, etc.) would be configured with no approval necessary, because the approvals would be done externally, outside of IdentityNow. As long as access is requested via the external solution, then approval processes would be followed, and access requests would flow to IdentityNow without approval, and be subsequently provisioned.

003.png

By default, IdentityNow allows access requests to be submitted natively through the IdentityNow access request user interface. Any accesses the IdentityNow might have with no approval would be requestable, and allow for immediate fulfillment via provisioning. If you are using an external access request solution with external approvals, anyone who uses default IdentityNow's access request interface could thwart your external approval process.

With this use case, SailPoint recommends as a best practice to configure access requests within IdentityNow to indicate that approvals are done outside IdentityNow. This is done with enabling the configuration option approvalsMustBeExternal in the access request configuration. When approvalsMustBeExternal is enabled (set to true), access requests submitted by anyone other than IdentityNow Admins will be blocked and receive an error when submitted from the IdentityNow access request Interface. Proper approval processes can be followed in the external access request system.

If you opt to not use this configuration, then SailPoint recommends performing approvals within IdentityNow. Leaving accesses unguarded, without proper approval is not a best practice.

Configuration


When approvalsMustBeExternal is enabled (set to true), this blocks access requests from the default IdentityNow access request interface, so that proper approval processes can be followed in the external access request system. Users submitting a request will instead receive an error message. Admin access requests are not affected by this configuration change, so they will not see an error message.

To configure approvalsMustBeExternal, make the following call via IdentityNow's REST APIs:

PUT /beta/access-request-config

with payload:

{
"approvalsMustBeExternal": true,
"requestOnBehalfOfConfig": {
"allowRequestOnBehalfOfAnyoneByAnyone": true,
"allowRequestOnBehalfOfEmployeeByManager": false
},
"approvalReminderAndEscalationConfig": {
"daysUntilEscalation": 5,
"daysBetweenReminders": 2,
"maxReminders": 2,
"fallbackApproverRef": {
"email": null,
"type": "IDENTITY",
"id": "ff80818155fe8c080155fe8d925b0316",
"name": "SailPoint Services"
}
}
}


The value for approvalsMustBeExternal must be set to true. All other values here are irrelevant, and are just used as an example. See the access request config REST API documentation for detailed information on how to use this API.