How to configure the RSA Identity Governance and Lifecycle system to prevent users from requesting exceptional access
Originally Published: 2017-06-13
Article Number
Applies To
RSA Version/Condition: All
Issue
Tasks
- First define the exceptional access:
- Create an SOD rule that defines the exceptional access:
Rules > Definitions > Create New Rule > Type: Segregation of Duties
- Process the rule.
- Second, define who can and cannot request the exceptional access:
- Go to Requests > Configuration -> Submission tab -> Edit Settings.
- Under Violations there are three options:
By default, these options are not checked. This means anyone can request exceptional access and submit the request. To prevent users from requesting exceptional access, the first two options need to be defined.
- The first option Show violations to the specified requestors determines who will see if their requested access creates a violation. Any user meeting this criteria will see a warning if they request exceptional access:
- The second option Requests with violations can be submitted by requestors determines who is allowed to request exceptional access. Any user that does NOT meet this criteria AND that meets the criteria of the first option will be prevented from submitting the request:
Resolution
Related Articles
Via L&G 6.9.1 Aveksa Application Roles Privileges Tab for a User 17Number of Views Role Analytics tab under Missing Required Entitlements displays technical roles as global roles in RSA Identity Governance… 35Number of Views After refreshing a user access review, the business source values for roles (role sets) display as null in RSA Identity Go… 30Number of Views Configuring an RSA Data Loss Prevention Network Internet Content Adaptation Protocol (ICAP) server and Exchange to monitor… 176Number of Views Requesting access to RSA Authentication Manager Google Compute Engine (GCE) image file for Google Cloud Platform (GCP) env… 100Number of Views
Trending Articles
Don't see what you're looking for?