logo

NJP

What's new in Vault in ServiceNow Vancouver Release? - Creator Toolbox

Import · Aug 09, 2023 · video

[Music] thank you [Music] thank you [Music] hey everybody good morning good afternoon and good evening and welcome to the first Creator toolbox of the Vancouver release cycle this is a show brought to you by the servicenow developer program where we demo all the newest latest and greatest features for every developer's toolbox my script says we are in the middle of the Vancouver release but this is actually the first live stream of the release content so be sure to check out our content calendar at devlink.sn Vancouver before we jump into all the exciting content let's do some introductions because I see that we have a very special guest here on the show today I'll kick things off my name is Laura McMann I just celebrated my sixth anniversary at servicenow which is very exciting and I am a member of the developer Advocate team alongside the next introduction which will be pranav hello everyone my name is Prana bhagat and I am a senior developer Advocate also here at servicenow I have close to around seven years of experience and that's about me let's I'll pass it to Earl hi everyone I am Earl JK I am part of the developer advocacy team here also at servicenow uh what has been with the company for about two years but before that was the developer for a bunch of different companies mostly in higher education before I joined servicenow and I'll kick it over to Jared hey good morning good afternoon everyone I'm Jared mundt I'm a product success manager here at servicenow I've been at servicenow for about a year now but prior to that did eight years out in the community and uh I love talking about Integrations free and premium security products and other things on the platform we are extremely excited to have you here thank you so much for joining Jared quick note in the upper right hand corner of the video I did a make sure my thingies were in the right direction that will be a clear indicator that this is Vancouver content so if you're ever questioning what version that we are presenting on check out for the graphics in the upper right hand corner and with that I will pass our conversation off to pranav to discuss all the latest and greatest things with the servicenow Vault take it away yeah now I'll pass it back to Jared because he'll be taking you will be showing us all these new features sounds great uh so servicenow vault is not a particular product it is a suite of products um so starting in the Tokyo release it Vault was launched and it had four products that were included with it and that was the the platform encryption the data anonymization code signing and secrets management Enterprise and since Tokyo that routinely just had features uh added to those and and even have had additional Whole products added to the suite and so today in in Vancouver it is grown from four to six products so since then uh in Utah the log export service the Kafka compatible log exporting was added and also uh now for Vancouver we have oh also also uh data Discovery has been added into the data privacy and the newest kit on the Block is the zero trust access so that'll be the demo that I finished with today that's the the new uh again premium products it's that is only available with the Vault Suite license um but as we go through a few of these demos today I'll sprinkle in some of the core products that have been added during at the at the same time as these premium products also just before you um start Jared I wanted to uh call out we have a nice active chat going along people excited about Vancouver and stuff like that uh right now the YouTube chat isn't coming through our streaming service right now so usually I will display people's comments on the screen for people to um engage with so that if people have a question for Jared or for any of us then we can answer them live we'll still do that if you're in the chat so can I chat um hey everybody saying hello over there um unfortunately I can't show it on the screen today but usually we'll show that on the screen but uh we still see you I just want to make sure everybody at home knows that we see you thank you yes and if there's a if there's any specific questions you think would be would be valuable please just uh read those read those and jump out um so yeah to understand Vault um like I said it came out in Tokyo it had four products some of these products are available as separate uh premium licenses they can be purchased separately depending on the needs of your organization and some of them are only available as the as the full Suite um so every time I talk about Vault I always go back to Tokyo [Music] um because all Tokyo was was a big release for core features as well uh if you if you've not yet played with data filtration um or the protected tables plugins um I always throw those out because usually if you're interested in Vault in the security products those those are some other free plugins that can kind of help your your take your instant security to the next level and then depending on if you have specialized needs Tokyo also had the S mime encrypted email plug-in for inbound and outbound encrypted emails and then also the skim clients if you're doing Integrations with identity management systems those are all came in Tokyo as well uh the quick I'll get through the history lesson and then get to the demos but um we always love a history lesson no problem with that yeah there's all there's always a lot of history especially with everything changing I mean we're talking about Vancouver right now which is what four days or something like that into early availability so everything's changing pretty rapidly based all right welcome to software right yeah and as little as we'd like to admit it a lot of people you know say and you know n is difficult so maybe people maybe aren't even yet on Tokyo so covering Tokyo is never is never harmful there's right and to get a good feel for the vault Suite um I I'll throw out the the Safe Harbor forward looking I'm not promising anything for the future but I will say that since Tokyo every release um and and even some store releases in between the major releases have continued to grow uh what you get with that Vault license so um the history lesson does kind of show the the pattern of growth and and just new features not for both the the free core platform but also uh the premium licensing so pass Tokyo into Utah the log export service was available that helps get you get things out of the um out of the instance very efficiently near real time uh if you've played around or done the data Ingress side of things with the integration Hub stream connect this is the the other side of the coin this helps you stream your logs uh out of the system this one is available as a separate SKU there is a similar to integration Hub starter there is a a free license for this but with the Vault Suite it does give you log export Service Enterprise which is a unlimited data option I have a quick question Jared is any of this testable on like a PDI or something like that or they have to arrange a specific demo from their sales team to see this so most of these features are available in a PDI log X or service however is is not um it has to be in a certain part of the data center to take advantage of those um it's it's the same reason why uh and the same Hardware actually behind the scenes that why you can't do a custom named instances on your PDI it's it piggybacks on that same network infrastructure so for example if you if you are in a uh if you're a partner with a vendor instance or customer with a subprod instance you will be able to evaluate log export though fantastic thank you so quick shout out to the developer.servicenow.com repository of pdis pdis being personal developer instances thank you Earl um the really exciting thing about that is that Vancouver instances are available so check those out if you'd like to play around with any of the stuff that we're talking about today and nice plug yeah yeah so under data privacy uh the the Tokyo data anonymization has continued to grow into a data Privacy Suite where it uh now has both an anonymization feature um to anonymize both in production and sub-production certain records but the data Discovery helps you configure your data classification rules and we'll help make sure that you know which fields in which tables your sensitive data exists and that can help you better manage that and so the the data Discovery is part of the Vault Suites and that will help you it comes with some pre-configured regex rules to help scan your tables and um if uh someone previously on your instance Maybe created some data fields or stored some foundational data I don't know everyone always uses Social Security numbers but any other the credit cards anything sensitive perhaps in the cmdb where it shouldn't be the data Discovery will help you find that um yeah I I used to work in higher ed and all of our higher EDS always had hospitals attached to it so everything became some form of pii at some point because like a name's fine an email just can be fine but combined with any other information I always become pii so half of our stuff that we were swearing about our health customers instantly became stuff that would have helped having Moore's kind of these kind of plugins so that's nice to see and one thing I can add on is Jared like out of the box I think we are supporting four things one is the email address phone number US phone numbers Social Security number and credit card number so that's out of the box supported so and we can also create custom regex also in this so that's absolutely yeah this this data privacy tool works very similar to the virtual agent uh sensitive data Handler plug-in where we have a a number of rules out of box to show you how to configure it but yeah it's definitely extensible for all your right like a healthcare organization might have uh ID numbers that are in a very specific format we want to be able to discover those and um and when we're cloning that's one of the major use cases um for this is is that way we know when we're cloning we want to either obfuscate that data or we want to just prevent it from being cloned completely um what else oh yeah since we're in the in the Utah portion of the history lesson there were some really cool features that came out um outside of vault as well in the core security platform uh the time-based one-time password uh for email and SMS is something that I personally have have tried to build myself and hack around on in the past so that's not a native feature um where uh previously if you wanted to do multi-factor on your instance you had to convince your users to set up a Google authenticator equivalent app on their phone but now we can do just straight uh time-based one-time password to an email an email address or a SMS number so further reducing friction for your users letting you crank up security but not really impacting your organization to do so also within the Adaptive authentication so what's what's what I see less and less of is the IP address controls strictly reducing or restricting which network IP ranges can access your instance what I see more of is moving to Adaptive authentication letting uh the more mobile and uh CSM engagement managers and and things like that we don't want to restrict it just to the the company IP ranges so adaptive authentication has existed since Quebec but in Utah we got an upgrade to it where we have a lot more granular rules and we can protect your rest apis and your soap apis so and we can even take it a we can even take that another notch and we can say on your rest apis you can do get requests but if you are not using oauth to authenticate to this API you can not do a delete action or a post action so it's it's very granular that's cool that got that got kind of snuck in into Utah without a whole lot of fanfare and so that's why I want to bring it up here in a forum like this yeah one of the cool things about our shows is we're we have a really good developer audience um anybody well developer and service now what does that mean anymore um anybody that does building creating uh analysts start doing more stuff in building um admins and stuff like that but um I know what is good about ourselves we try to connect it to what's important stuff like that and I know a lot of us are developers or we're developers on the platform and stuff like that but a lot of things that Jared just described back from like what happened in Utah and um leading into today it's good for us to have because we often forget that a lot of our people that are using this as end users are uh field service or people that are on the move and so having all these these easier ways to get into your instances uh and not have to jump through hurdles of security every time you need to fill out a ticket or um answer a field service management request or something like that uh helps because someone might be jumping IPS a lot so they have to have a different kind of security someone might have the same IP on their um um on their thing but they might be moving around or um or like the idea of they don't have access to the VPN or they do have access to a VPN and how what complicates access at that point so having the ability for your system administrators and designers to decide how they want your people to be able to access your instance just makes it better and more streamlined to standards across the industry so that's good stuff that is happening in my security security is very important everybody knows it um it's just like right when you make it harder for your users then security becomes your enemy but security is still important so having options and having different ways to do it is always better very well said very well said and we'll definitely come back to that because that new feature uh zero trust access will show show that here in a couple of minutes uh and and we'll go right into what Earl was just talking about um one last free thing in Utah um you may have noticed this isn't available uh this will be installed by default when you upgrade to Vancouver is the security Center this is a new built from the ground up uh modular security Center that's going to be phasing out the previous ISC instance security Center so similar name but it's a it's a different product with a wider scope of what this is touching so we won't go deep into that we uh out on we'll have a link in the notes to the privacy and Security Academy out under the Community YouTube channel and that's there was a I think we did a 40 45 minute Academy specifically on this so but the security center it's it's similar to the ISC where it gives you a score gives you recommendations about what options you have to raise your score but it also gives you the the details here's how it's going to impact your users if you flip all these switches and and try and get the highest score so so that's new and the thing I like about this the new security Center is that it is extensible through instance scan rules so you can build your own checks you can you can make your own rules and and that way it's kind of a desired State configuration where the admins can can make sure that nobody else who has permission to their instances is making things go the other direction um so that's yeah there here we are that catches us up through Utah um so Vancouver um the Vancouver has some really cool core features um and these are available for everyone regardless of your license level uh so I'll shout outs and then I think there will be some other life coding happy hours as in some other episodes going deeper into these but I will I will shout them out in case you have not heard of them before and that would be security attributes is the first one uh this is a Edition um this bolts on to the ACLS and also to the data filtration rules and security attributes are not about the records that you're looking at but it's about the person accessing the records so these give you some rules uh and some script fields to make determinations kind of like kind of like the Adaptive authentication um it's it's session based um so it doesn't know who current is it doesn't know current dot manager and things like that but it does know the the session of the person who is accessing it and conditions on the records that that person should have access to and because it doesn't need to know about the current record uh these when you build these things they are cached and they are very fast so if you cut the platform Academy that was done earlier this year where we did a full hour deep diving into how ACLS work and the different parts of them and which are cached and which which ones are evaluated on every single field every single time uh this this new security attributes will play very nice and will help you get better better control um over those records that's cash money yeah I saw Lauren roll her eyes so but now we're adding in another layer of of options to configure your ACLS um right back in the day before data filtration before before the security attributes you had ACLS and you had before query business rules now we have data filtration on top of that now we have security attributes that can say right it makes it it could make it even on another layer more difficult to troubleshoot right like if if a A salesperson they say I can access this report when I'm in the office but I can't access it when I'm at home right that could be a little bit more trouble for the system administrator to troubleshoot so what we've released in and Vancouver is a new tool called access analyzer so instead of having to turn on debug security and Wade through 90 levels of of little icons and and searching we have a a page that is built specifically for that you put in which user or group or role and which table or even which particular field on which table and it will give you the history here's here's which data filtration rules here's which before query business rules may be impacting that here's the different layers of ACLS here's what you know here's why they can or cannot access this and so I believe that's uh I can do a shout out to an upcoming live coding happy hour um that's going to go deeper onto that particular tool but that is that's probably the the I don't know if that's for me if that's cooler than security attributes but I think uh for us segment of the audience that's going to save them a ton of time nice um I I also I feel like we have to do this one because it is our first episode of the season but um I think Jared just referenced live coding happy hour right now you are watching Creator toolbox um just FYI we have a couple of shows and we have a few shows actually at this point that we run on this YouTube channel and on podcasts uh but we have different shows Jerry just referenced live coding happy hour it's another show that happens on this channel so you're watching this on YouTube on the developer program YouTube channel and at this point you can go to the upcoming live streams section of our Channel homepage and you'll see that we have mostly two shows lined up for this coming season um on YouTube specifically in one of them is Culture Creator toolbox what you're watching now hi uh this one is demos and talking about product features um usually partnered with a product manager and the other show that Jared's talking about is live coding happy hour which is a little bit more relaxed and we try to go more into just straight trying to figure out how to get something to work and seeing all the pitfalls and just live demos but not really demos because we it's usually unscripted and we're just trying to dive in so that everybody can seize the same experience that you might exceed when you start diving into it too and then since we usually have a lot of developer Advocates or MVPs or um product managers sitting with us hit the oh while you make it at home an expert right away being a fun little different kind of show as opposed to um learning about the feature then we try to dive into the future that's our one-two punch for these two shows that's what Jared is referencing Jared's a veteran of our shows so live coding happy hours in his blood I um that's one that was the first show that I showed up on when I was a developer three companies ago so like a lot of us have our starts on and a lot of community building around live coding happy hours near and dear to our hearts so as much as we're in Creator toolbox right now a little advertisement for to join us for live coding happy hour because we're a little bit more relaxed we were more interactive um with the the audience and it's just a good time yeah and it's a good time to plug into the live coding happy hour that will happen this Friday on access analyzer that that Jared is talking about so you can come and see uh me play around with access analyzer in morning in India morning time so yeah that's there oh Earl bringing back good memories uh I'll never forget how how uh intimidated and and sweaty I was after doing my first uh live coding how to I don't know if there was 50 people watching it but yeah it felt it's it's not a um it's not a relief season if there's not one episode of at least a couple of let's just ending the show super sweaty and anxious they're like what did it what just happened it's usually me so good yes yes looking forward to access analyzer and also seeing what how the the the community uh feedback from that is and and if you if you reach out to me with any of that I'll make sure to get that right in the hands of the product management um but also this is the point where I usually uh shout out to the idea portal out there on the sport instance if you if you have a tool if you want new features to it um the product managers do monitor the idea portal so so I'm I'm caught up on History that's what's in the core um part of Vancouver but we have the premium part of Vancouver these vaults licensed features uh Vancouver has added on a couple of of really fun options for us um the the first one is part of the column level encryption Enterprise which is you may have also heard it call this platform encryption uh that's a bundle with the cloud cloud encryption and column model encryption Enterprise that's where this lives um previously this this um was a lot of Key Management framework records with their related lists and you had to go to three different places you'd have the the cryptographic module the module access policy and an encrypted field configuration and you had to kind of switch back and forth to see who had access to what but now in Vancouver um I've upgraded my blimey instance over to Vancouver and I have some and I have some a couple of different demo for within the column level encryption space and so as you can tell this this menu here is not very friendly unless you've been looking at it for a couple of years but brand new in Vancouver we have this new view access policies so again I'm on the cryptographic module here's my encryption key down here AES 256 we can drill down into that there's some other key management things over here resource Exchange this isn't the this isn't a training for column model encryption but the brand new feature in Vancouver is this view access policies page and so we take this web of related lists and we're turning it into something that that an auditor could look at that a assist admin could look at without having to invest um an afternoon in in drawing things back up so here what we can see is on my uh my sample system property lockdown I was doing an experiment with in Secrets management and protecting [Music] system properties that had a type of password too but that can be a that can be a demo for a different video but here we can see that by default we are rejecting people great um we don't have any logic in here that would allow a flow or a scheduled job running as system to get access to that and then we can add in a rule and tweak it as necessary so that's that was something that was easy to misconfigure in the past as we go down we see which roles have access we can see oh I'm giving Ito admin access to this I'm not allowing impersonation and over here under under scope um looks like by default I'm not I'm not allowing Global Learning one to to do this and I don't believe I have any script to type policies that's another feature of what you get with column mobile Enterprise as opposed to the out of box the standard column level is the ability to go beyond just giving access to things via a role you can say this scope can access things or this script defines and then the best part is this lower section here great uh great this I tell admin has access to this encryption policy what does that actually mean oh is that is that one user or is that you know accidentally giving 3 500 users access to this data so here we can see for this particular uh cryptographic policy that I clicked into uh My Demo user Vinnie ITIL is the only person that can access this particular thing so prior to Vancouver this would have been me clicking around through uh three different records and and looking at the record on their related lists but now I get to see this all on one page Jared speaks so nicely about how about a lot of these things oh and are we giving access to accidentally to hundreds of users it's like a we've all been there Jared saying it really really nicely but most of us have ever done security has stumbled upon oh a lot more people have this role than I expected it sure right you grant a role and then it's like hmm why did my instance stop working yeah or nestled to like nestled roles like oh I gave this person just one role you're like yeah but that role had all these others inside of it right especially ambiguous like uh product management things right like within uh agile right things that sound like there might only be three people uh you know somebody's troubleshooting ACLS and they give it to everyone temporarily and then that you know eight months later everyone still temporarily has that role yeah it's a little bit by Design too because I mean there's a situation oh I granted this access a person to scrum tasks which grafted them access to Agile development which kind of them access to project management which instantly got to the access to other ITIL stuff and now they're also approval users somehow yeah it's just like well it's a platform and we want it to be connected in those ways but now but we also want to make sure the security processes are pretty transparent and clear absolutely yeah uh I'll shout outs no not not yeah back to back to Vault uh one thing I did not mention before um is some of these are available as separate separate skus separate products to license uh for example the pro the platform encryption is available separately um now in Vancouver uh the secrets management Enterprise is available to purchase separately so one of the the not new in Vancouver feature but one of the critical differences between Secrets management core which is installed on your instance already whether you knew it or not um and and the secrets management core is protecting uh so it handles the encryption for your password 2 fields those are those are so much more protected now than they were 10 years ago and secrets management Enterprise gives you the option for to to do itom Discovery into highly sensitive parts of your network where servicenow doesn't even know what the username and password or rather what the what the password is to get access to those systems so you can encrypt that on your mid-server and your Discovery process would be transparent uh identical to discovering all of your other systems but for those key critical network subnets servicenow does not have the the key uh it's a little bit like a little mini version of edge encryption for that so um that that can be now will purchased separately without having to purchase the whole Vault Suite uh co-signing a data privacy while we're on this topic um are only available with the Vault Suite log export service can be purchased outside of the alt suite and zero trust which is where I'm going to right now um is in Vancouver only available as part of the Vault Suite so any deeper than that please talk to your account representative but that's that's the high level what I know about the licensing so no need to go any deeper on that because this is all about the cool features that's a good point to clarify um so because sometimes we get questions in the chat or in the comments following these presentations uh none of us are at Liberty really to go deep into licensing or cost of any of these fun features that is why y'all have lovely sales associates and solution Consultants to chat you about that so just starting that off from the beginning too early in some I do certain docs have zoom ins on those links on everything that you're hovering over they they do I don't know if I don't know when that started but when in this table when I hover over images or the the text and it's actually selectable text um it's super extra but I'm kind of digging it me too I'm like is that I thought that was a browser extension I didn't know that was part of our doc sites no I used to do that right with the Mac track pad and just pinch and zoom and you know kind of fly into a portion of a site but no that's that's just the our standard docs site uh cute maybe they maybe they need to share what they've been doing for the Vancouver release themselves because usually we have to ask people including our own selves to zoom in on our browser but we haven't even had so shout out to the docs team I guess exactly so zero trust um I mentioned this a bit earlier Earl mentioned it we want to make it easy for people to do their jobs we don't want to add a lot of friction but what we want to stay secure so um specifically zero trust access this is a premium product that uh works with the core adaptive authentication product and so what we could do before what everyone can do with your core license is we can detect and we can deny access to both interactive sessions and now rest soap and um your API access based off of Ip ranges based off of devices so for example the in in Tokyo The Trusted mobile device came out where if you're on a trusted segment you can register your device and then you can take that device into um parts segment Network segments on the planet to where they are they might not meet your other network [Music] approval ranges but because your device is already trusted um that device can still be used to interact with your servicenow instance same things certain roles and groups maybe you say if you are a security admin you can only log in from the corporate IP range but if you are a requester or a regular fulfiller you can log in from anywhere else right that that straight up or down rules are available through the Adaptive Authentication but now in Vancouver with your Vault Suite you get zero trust access and over here in the red this is the the bit that is really cool so if you are we can we can set this up um it's into really any any flexible combination that will meet your security guidelines so the example I usually go with is a somebody that um these maybe there's a sales manager they have access to all the all the sales data they have access to a bunch of sensitive things but they're traveling so we want to we want to still let them log into the instance and be a requester we want to still give them catalog access if they need to request a new laptop battery if they need to requests any any amount of things that are in your employee service center catalog but we might not want to let them have those extra roles if they are traveling or you know whether it's outside of the the corporate office or onto the other side of the globe so this lets you do granular and it will reduce access another thing would be with assist admin right if this admin is taking a vacation we would want them to still be able to log in and maybe they're working remotely and we want them to log in and be able to have their ITIL role but not the admin and security admin roles so with zero trust access we can selectively prune their roles at uh at login time what I love about this too is that I think it reflects a lot of I think it shows servicenow's dedication to responding to the market right like with covid like you see a lot of people now are more like adapting to more of like a digital Nomad style of working even if it's just home and office versus which was exclusively office before and so with that change comes has densities from Administration from like the networking side and so I love tools like this I obviously like you know I feel like security is like the unsung hero of All Tech because it's never the people the ones that are like on the front lines like yeah security but it's setting these things up from the get-go that Propel everything else to like such a higher degree of like confidence in this software so I just really wanted to shout how much like I personally appreciate how reflexive of that Trend like this is like that's so cool Hey Joe can I ask you a question too um regarding uh you just said a comment um pruning the roles if they are show up maybe in a location you're not expecting um but they you want to still let them get into their ITIL stuff instead of their admin stuff you said prune and that to me feels very um not destructive it's not the word I'm looking for but is it does it restore access if they get back into the normal looking thing so it's not really pruning it's just like a temporary it's really just a temporary reduction instead of correct yeah it's not actually get out of here yeah yeah it's not remove it's not changing your assist user record at all it's not removing roles it's not removing groups it's it's just at at the run time when it right you everyone knows you add if I give Earl a new role you have to log out and log back in for that because we have to you have to have that role at at authentication time at so this this runs at that same that same early layer and when it's building your session uh you know that GS has roll thing into the cache um it's it's just dropping a couple um behind the scenes right before it builds you all your your session information um very nice and and Lauren is spot on yeah it's it's the security that adapting to the market uh and our other Integrations and partners um are are doing the same thing they keep adding on new features so for example down here at the bottom left we have identity provider attributes your your single sign-on idps um they are they've made a lot of uh improvements over the last couple of years as well right especially with the work from home Revolution and uh needing to track what's going on so uh in in in My Demo we actually are looking at an identity provider attributes so at login time uh the demo is using OCTA but but I'm not I'm not singling out OCTA there the industry is moving um to be more granular and and more intelligent so um what we'll see is uh if if the IDP attribute if they say your risk is over a certain threshold um remove the roles otherwise right it doesn't the example I'll have is it doesn't we're not looking at Network subnets or you know we're not looking at country codes we're just looking at what is the what does OCTA think the risk is and and off to you know that's a that's a separate demo and what do we have on uh available to us on that side but we did we did get a question from um the audience and we'll make sure to say ask it live on here so people watching after the fact can hear it that someone asked if a admin goes to a disallowed geolocation and gets that temporary access or that reduced access I mean not temporary and they go back to a regular geolocation will it cause a re uh re-authentication for them or will it be I I guess it's based on login so yeah they would need to yeah I don't I don't think it would detect um and and prompt a a relogin I think you would just have to to know um to log out and log back in um so Jared like I think what I heard was like it's a session based login so if they are in a geolocation which doesn't let them access the platform as an admin then once they're back to the location which which lets them access with admin role then I think they will be able to do it they just have to log out and login back it's a session based thing but to this question like what about vpn's Jared like what will happen if somebody is using VPN I think it would be the depending on the rules uh if you yeah if you're if we're if we have the network based rules and if you meet all the meet all the checks whether it's a corporate VPN or whether someone is purchasing a private VPN to you know log in from Germany and you're really in Canada um yeah it all is going to come back come down to your your Source Network address and and the device that you're logging in from um so this yeah uh this this is uh we continue to get granular right we talked earlier about IP address control and it was just a strict up or down you know for all interactive users all um all rest and soap and all your apis you know are you in the coming from a network proper Network range or not an up or down now with adaptive authentication it's we can be more granular with roles in groups and devices and then zero trust lets us get even more Surgical and we can prune particular roles good good adjective there it's uh so the one of the great things about being in the security space is that um when we demo it's largely configuration based because once everything is set up the demo is largely transparent right if we're encrypting fields for our financial services operations tool but the whole point of of having a secure system that's low friction is that it's it's they don't need the end users don't even detect that we are doing full disk encryption that we're doing zero trust access that we're doing data privacy and subpro right it's just our so a lot of our vault demos out there in the world look a lot like a CSM demo or look like a itsm demo because really we're just making those other workflows work more secure and it in in many cases you can't even tell that the these free and premium security products are in place so um I can walk through what configuration options we have with zero trust but um but again the zero trust demo looks a lot like just having a regular user at login.do logging into the instance but because so much of that is just obfuscated behind the scenes thanks so I'll flip into one of our quick uh on-rails demo um here so like many of our security products we must be uh elevated to security admin and then we'll go into our zero trust access configuration and I have one rule here where we are removing ITIL outside of the trusted Network and inside of this policy I have two conditions one is and this is these are you can look at these as ores so kind of similar to a uh when you're putting in rolls on an ACL right do you have ITIL do you have ITIL admin you don't you these are not ands These are ores but for example uh it if I'm on a if trusted network is equal to false this rule will kick in but also like we mentioned earlier with the IDP attributes um if my the IDP that I'm logging in with is this particular OCTA one and the attribute returned during that that saml handshake redirection uh there's some attributes in that Json if the risk score is greater than 80 that also this will evaluate to true and the rule will kick in so and because these are all just controlled by records as well you could probably tie like flows to them and have things be like notified and things like that correct oh I like I like where you're going with this I have not plug flow designer execution side of things true like um I guess I have a similar question um when a person gets the reduced access uh are they notified of the reduced access as they log in that is a great question let's let's click through to the next couple of options [Music] yeah so we will log out as our admin user and I will again just quickly log in here and we are notified with our info Banner at the top of the screen so um I I have not dived into the behind the scenes and and I I can't quote on how how customizable this is and and what your options are but yes out of box Earl when when someone does meet a policy um notice that it doesn't we're not giving away we're not uh like with a lot of security products we're not specifically telling them oh you've logged in from here you need to log in from here to get full access right yeah like hey we didn't reduce you broke the rule here's the exact secure right so so we're intentionally we're intentionally vague but we are letting them know something is different for this session um yeah yeah and if if they do want to dive deeper um we do provide this correlation ID at the top of the screen to like for example if it's if it's not working quite right or if if you're setting this up for the first time and you're trying to fine tune it uh this will be very helpful for you for those things behind the scenes so uh so the the final click through here is I'm logged in I will have access to my uh to my catalog my portal all the things but um remember I do not have um I told any anymore so when I try and go and click in to something that does require that I get the the same thing that a uh a regular requester would get if they happen to know the exact URL of where they're going so I'll be in this example I'm logged in as me so if I have all my bookmarks and I'm trying to deep link into particular workspace or a particular record we will get the the proper access denied messages and so that's that is the uh the happiness of configuring this this new product I think again you get so lost into how long we've been in the platform or anything but I just think about imagine not being able to do this stuff or having to do this stuff manually like the the necessary guardrails and fences and coding that you would have to put to just be able to base things off of uh what what it what a trusted network is more than that like geolocation all the things that goes into that but um now we have a a simpler a simple interface a lower code solution for admins to be able to set that up pretty quickly and to adjust on the Fly which is even better too um because what if it's like oh they that score of 80 on the uh Samuel handoff was a little too aggressive I mean we need to tone it down a little bit thinking about yeah before all the what was necessary to change the number from 80 to 79 in terms of trusted networks and geolocation and IP addresses and where everybody is and stuff like that and then the roles that go down and up based off of that thing like I that's why I'm happy to be in the servicenow ecosystem because it's like why would I want to waste my time let me focus on the fun stuff interesting stuff yeah yeah and and so this this product um you'd think back to the last five years ten years for some of us um it's not just production right there's there's been times where we want to uh we could we could use this same product in a sub prod to to limit maybe we're doing a special something in Dev and we only want to let two people have admin right so we could just configure a rule that says if you're not person A or B strip admin at login right and then once you're done with your special Dev or whatever your whatever you're researching you open it back up for everyone so um yeah just another another tool where we're doing uh configuration rules and and being less reliant on scripting and and those behind the scenes uh engine blocks and I can say one thing like uh when I sh when we showed this particular feature during the episode of tech now so some of the developer reached out to me they said they built similar kind of a configuration and it took them I think two months or two and a half months to even reach half of what we are currently offering so kudos to the engineering team who put effort in that it's yeah absolutely yeah and what what is this page we're looking at oh this uh yeah I was I was done with the demo so I just put on uh my default uh advertising page we're we're trying to spin up the platform privacy and security uh it's it's I think under two months old um it's it's a subsection out under the Community under now platform uh privacy platform and security and so that's where we will be posting things like the Privacy and security um Academy sessions that I mentioned earlier oh actually here's the one I mentioned earlier uh the security Center one uh so we're we're posting those out here uh some of the other PMS uh randier who's doing some great things with authentication um here's looks like rest API auth Scopes that's the API side of adaptive authentication so here here's a little how-to on if you want to force everyone to use oauth and get rid of basic off in your org we can do that with these rest API authentication scopes um so yeah this is our uh our little part of the community so I'm done I'm done sharing um well thank you so much I'm done and we're done um no Jared thank you so much for joining us here today uh I'm so amazed by everything that we got to see I'm very excited to see like the trend of how the security product has started and grown throughout Tokyo Utah and now Vancouver so this kind of brings us to the end of our first ever Creator toolbox for Vancouver a quick reminder to the crowd that we have an entire week full of content we have a break point episode coming out tomorrow we have a Blog coming out on Thursday and we end the week with not only a live coding happy hour but also a replay of the tech now if you happen to miss it last Friday if you'd like to follow up with Jared on any more Vault related things do you have any I don't know what that is um do you happen to have any links that you'd like to plug to the crowd today I I'm gonna just try and get that privacy uh that platform privacy and security section out on community uh that's that's where I'm gonna I think that would be the the top one any place that they can reach out to you if they have any additional questions sure I'm at servicenow uh so Jared M at servicenow.com or jared.munt at servicenow.com or uh also out on Twitter and the snf's uh chat or LinkedIn do you have a short Alias for your servicenow email address I do look at this Celebrity Status over here very nice um that all the stuff you can see remember you can go to dublin.sn uh you'll if you want a quick visualization scroll go to that link and scroll all the way down and you'll see a calendar that has all that stuff on it it looks like this on your screen um it has all of our shows coming up and yeah easy visualization thank you Lauren for creating that um cool anybody else have any other announcements they want to plug in front of any final words now I think I'm good just join us for the access analyzer life putting happier that's happening this Friday at 2PM IST so yeah that's about the last plug IST ISD make sure you look up what that means for your time zone because um just like we did earlier this year for our Utah release uh the Times Really um surprise some people so make sure you take a look at that um if you want to tune in live otherwise feel just like all of our shows um we get a lot of views after the fact when people start looking up topics so hi to everybody let's watch them afterwards and that being said thank you all for joining us and we'll catch y'all on Friday on our next live stream have an awesome day bye bye [Music] hey everyone let me check this thing Jared is the best glasses thank you [Music]

View original source

https://www.youtube.com/watch?v=UC67tOCRKTc