Transcript
I'm here to give a brief demo of the Service Catalog for IdentityIQ version 3.2 application. So with this new release, you can extend the scoping functionality of IdentityIQ to the ServiceNow interface. And that's what we will demonstrate today. By enabling scoping in IdentityIQ, users can be restricted to view and request accesses based on their eligibility. So until now, ServiceNow displayed all requestable accesses. However, you now have the option to view all accesses as before, or only those that are scoped. Which means ServiceNow will be able to read configurations related to scoping defined in IdentityIQ, and display search results personalized for the user. So this version of Catalog also improves performance and displays search results in a tab format. This feature will be compatible with IdentityIQ 8.4b2 and future releases. It will be also available with IdentityIQ 8.5 version. The ServiceNow versions with which it is certified are Yokohama, Zanadu, and Washington DC. So now let's login to ServiceNow as an admin user, and navigate to SailPoint IdentityIQ for Service Catalog application. Here, you can see that a new parameter has been introduced, which is Enable Advanced Interface, which is disabled by default. So let's assume scoping is not enabled in IdentityIQ either. As a recap, let's look at the existing functionality. Now let's login as Able Tutor, who is requesting on behalf of others. I will select Able Tutor and go to the Select Access page. Here, you will observe that all requestable roles and entitlements are displayed in single view. Now let's go back to the Setup page as admin user and enable the Scoping parameter. Save the changes and let's again login to Able Tutor and check the difference in the view for Select Accesses. We now see that the search results are in two tabs, that is Roles and Entitlements, and all search results are shown. Now we'll go to IdentityIQ and enable Scoping via Global Settings. Here, I have enabled Scoping using the Attribute Location. Now accesses and users under the scope of location, say Mexico, should only be accessible, and other accesses that are out of scope should be restricted. Now let's assign Able Tutor to this scope in IdentityIQ. Now let's login into IdentityIQ as Able Tutor. Here, we can see that Able Tutor can now only request for users within his scope. So let's select Able Tutor and see what accesses it has now. Here, he only has access to these three roles, and since Account Editor is not under his scope, it is now restricted. Now let's look at the ServiceNow experience. Here we can see that all other users are disabled for Able Tutor, and only Abraham and Alia are enabled for requesting accesses. Let's again select Able Tutor and observe the difference in the accesses it has now. So, only these three roles are visible, which are within his scope, and all other accesses are now restricted. This is how we are now able to replicate IdentityIQ Scoping into ServiceNow Catalog. I hope this demo has been helpful. You can reach out to your CSMs for further information. Thank you. Microsoft Mechanics www.microsoft.com www.microsoft.com