Blog
Multi-Account Access Requests
Author
cameron_wilson
SailPoint
SailPoint® is excited to announce the release of Multi-Account Access Requests, which is a new access request feature available to all Identity Security Cloud (ISC) customers.
The Problem
Customers often have users with multiple accounts on a source. In that case, access requests need account context to support accurate provisioning and deprovisioning.
Prior to today, you had to manage access for users with multiple accounts outside of Identity Security Cloud or you had to define an instance of the source per account type which was highly inefficient.
The Solution
Multi-account access requests allow the requester to choose the right target account when requesting or revoking access for a user who has multiple accounts on a system. This feature streamlines the application onboarding, entitlement management, and access request processes for our customers. By including account context in access requests, we ensure accurate provisioning while reducing system overhead and configuration requirements.
The key benefits of this feature are improved productivity and governance. By supporting access requests for any accounts, we simplify the source configuration process and make access requests more straightforward.
Who is affected?
All SailPoint® Identity Security Cloud Access Request customers will now have the multi-account access request feature.
Action Required (Customer facing)
Make sure your source’s correlation logic matches all accounts for each user to their identity. If you have previously configured a separate source per account type, you’ll need to plan for consolidating them into one source to be able to take advantage of this feature.
Update: API Details
If you have scripts which use the create-access-request API endpoint, there is an update to the request payload that must be applied to take advantage of this new functionality. Refer to that API documentation for details. The new payload has been applied as a non-breaking change, so existing scripts will continue to function as they always have, supporting requests for users with one account on the target system.