User entitlement

Introduction

You can create user entitlement certification campaign to certify user application accesses.

Steps to guide you with example

  1. Create campaign
  2. View campaign
  3. Edit campaign
  4. Pause and resume campaign
  5. Cancel campaign

1. Create campaign

Navigate to Applications -> Access certification -> Create campaign

  • General setup
    Specify campaign name, optionally add description, select User entitlement campaign type, and priority.

    3444
  • Scope
    Select applications to review accesses in this campaign. All users that are entitled to the selected applications will be included. To filter this campaign's scope to a subset of users, use Include only option to select specific users or users of groups, or use Except for option to select all entitled users except for specified users or users of groups. If users or groups are added in Include only section. Then, Except for configuration will be ignored.

    - Scope applications
    
        [block:image]
    

    {
    "images": [
    {
    "image": [
    "https://files.readme.io/2880865-scope_applications.png",
    "2880865-scope_applications.png",
    3444,
    1970,
    "#000000",
    null,
    "64f9cd459203c500195af289"
    ]
    }
    ]
    }
    [/block]

    - Scope users
    
        [block:image]
    

    {
    "images": [
    {
    "image": [
    "https://files.readme.io/4324e39-scope_users.png",
    "4324e39-scope_users.png",
    3446,
    1968,
    "#000000",
    null,
    "64f9cd4780df98002f505adc"
    ]
    }
    ]
    }
    [/block]

  • Reviewer settings
    Select reviewer to certify accesses for users. There are 2 options to select reviewer.

    - **User manager**: a review notification will be send to the manager of each user in the campaign.
    
        [block:image]
    

    {
    "images": [
    {
    "image": [
    "https://files.readme.io/874982d-user_manager_reviewer.png",
    "874982d-user_manager_reviewer.png",
    3430,
    1966,
    "#000000",
    null,
    "64f9cd487b8a340f926d566a"
    ]
    }
    ]
    }
    [/block]

    - **Specify reviewer**: search an user and add single reviewer for all users in the campaign.
    
        [block:image]
    

    {
    "images": [
    {
    "image": [
    "https://files.readme.io/33dd51e-custom_reviewer.png",
    "33dd51e-custom_reviewer.png",
    3428,
    1966,
    "#000000",
    null,
    "64f9cd49df96440025fd0186"
    ]
    }
    ]
    }
    [/block]

    You can choose to log reviewer's decisions to know about each user's entitlement. There will no change in users' entitlements. Otherwise, you can choose when reviewer's decisions should take effect.
    
    - **When the campaign ends**: Rejection will trigger revocation of entitlement and deprovision of account according to the lifecycle policy for application once campaign will end.
    
    - **Immediately**: Rejection will trigger an immediate revocation of entitlement and deprovision of account according to the lifecycle policy for application.
    
    - **Let the reviewer decide**: Reviewer can decide to revoke entitlement immediately or when campaign will end.
    
  • Campaign supervisor settings
    If you wish to add other users to help you to track the progress of campaign. Then, you can add one or more users as supervisor of the campaign. They can track the progress of the campaign along with you.

    3444
  • Schedule
    You can either start campaign immediately or select a start date and time along with a frequency to re-run the campaign. Duration of the campaign should be between 1 to 365 days for reviewer to certify accesses.

    - Schedule immediately
    
        [block:image]
    

    {
    "images": [
    {
    "image": [
    "https://files.readme.io/29a1e73-schedule_immediately.png",
    "29a1e73-schedule_immediately.png",
    3448,
    1968,
    "#000000",
    null,
    "64f9cd4bc27b710e3f6f3391"
    ]
    }
    ]
    }
    [/block]

    - Schedule later on
    
        [block:image]
    

    {
    "images": [
    {
    "image": [
    "https://files.readme.io/416529c-schedule_later_on.png",
    "416529c-schedule_later_on.png",
    3444,
    1968,
    "#000000",
    null,
    "64f9cd4c25cffe000de7f4b4"
    ]
    }
    ]
    }
    [/block]

  • Reminder and campaign end
    If you wish to set reminder for reviewers. Then, you can specify the number of days to send daily reminders to reviewer before campaign ends. You can define the action for unreviewed entitlements after the campaign ends.

    - **Take no action**: There will be no change in the entitlements.
    
    - **Approve all**: All entitlements will be approved automatically.
    
    - **Reject all**: All entitlements will be rejected automatically.
    
    [block:image]
    

    {
    "images": [
    {
    "image": [
    "https://files.readme.io/f3723da-reminder_campaign_end.png",
    "f3723da-reminder_campaign_end.png",
    3444,
    1970,
    "#000000",
    null,
    "64f9cd4dfa510100197ba4c6"
    ]
    }
    ]
    }
    [/block]

2. View campaign

You can select a campaign to view its configuration details and progress.

3438
  • Campaign results by reviewer

    2130
  • Campaign results by entitlement

    2124

3. Edit campaign

You can edit description and priority of the campaign.

3446

4. Pause and resume campaign

You can pause the campaign.

3438

Once campaign is paused. Then, reviewers will no longer see campaign to certify the entitlements.

3436

You can also resume the campaign.

3438

Once campaing is resumed. Then, reviewers will start seeing campaign again to certify the entitlements.

3440

5. Cancel campaign

You can cancel the campaign.

3444

Once campaign is cancelled. It will be no longer available for review.

3442

💎

Aakash Prajapati, IBM Security