Blog
New Emergency Access Management Role
Author
robgarrett
SailPoint
Beginning today, the ARM web application now supports a new permissions role called “Emergency Access Standard User”, which allows admins to provide their users a dedicated role to access only emergency access end-user related functionality.
The rollout of this new role will not affect any current users. If any current user is included on an EAM profile in any capacity they will automatically be granted the “Emergency Access Standard User” permission, so no action is needed from admins to maintain their current access.
If you have users currently set up with standard roles purely to be able to access EAM, you can now change their roles to only include “Emergency Access Standard User”. This will allow you to better maintain a model of least privilege access within ARM.
The following roles are also now removed but will have no impact to end users:
- Emergency Access Approval
- Emergency Access Request Creation
- Emergency Access Review
- Emergency Access Profile Owner
- EAM Administrator Log Upload
- SAP Change Documents Extraction
- SAP Change Documents Viewer
- Client Account Administrator
FAQ’s
- Will any end users be affected as a result of the introduction of this new role?
- No, all users who previously had EAM access will continue to have access.
- Do admins need to take any immediate action as a result of the introduction of this new role?
- No, as no breaking changes are being introduced.
- How would SailPoint advise admins to utilize this new role going forward?
- Any user who requires access to EAM functionality must be granted the “Emergency Access Standard User” role in order to access the EMERGENCY ACCESS side navigation menu. You can now remove the “Standard User Access” permission role and EAM only users would only see the EMERGENCY ACCESS menu.
- What is an example use case?
- As an admin, I previously assigned the “Standard User Access” role to users who only needed access to EAM functionality, but they were still able to access other features. Now, I can assign those users this new “Emergency Access Standard User” role to maintain their EAM access and remove their “Standard User Access” role to remove their access to other areas of the web application.
- Will this impact the ability to see or grant access to the EAM PROFILES configuration menu?
- No, the EAM PROFILES will continue to be accessible by users assigned the “Emergency Access Profile Administration” role or the “Emergency Access Reporting Super-User” role.
- Why is SailPoint removing permission roles from ARM?
- These roles were for legacy functionalities that no longer serve a purpose, and as a result, we are removing them from the application.