Platform Privacy & Security Academy: Introduction to ServiceNow Zero Trust Access
hi everyone Welcome to our platform privacy and Security Academy section uh the topic that we're going to cover today is uh introduction to our service now zero trust access my name is Fergus Celine I'm a senior outbound PM in platform pricing security team I've been with servicenow for almost four years uh with me today run DRC rondier would you like to introduce yourself thanks everyone for joining in uh we are super excited for this session uh and I know it's early morning hours so I really appreciate it my name is randhir I am a product manager in the platform security business unit uh I have been with service now for more than five years prior to servicenow I have worked with Oracle and Verizon in service now my focus areas are anything and everything to do with integration and authentication that covers uh multi-factor authentication single sign-on or certificate based authentication adaptive authentication and zero trust access I'm super excited for this session uh and looking forward to have some great q a after the end of the session thank you Randy I appreciate it so before going to go any further as always we have to start by reminding you that we might talk about things that's on the roadmap since we're publicly traded company There are rules about making forward-looking statements so please um uh remind we would like to remind you that please make your purchasing decision based on the product as it exists today so the agenda that we're going to cover today we're going to talk about the unique business value of servicenow volts and we're going to talk about uh our main topic introduction to servicenowable which is the zero trust access the product brand new product that we're coming up as part of Vancouver release and then Rondia will go over the demo and then we'll get into the customer engagement channels as well as the Q a sessions so service nazare trust access as I just mentioned earlier that will be coming as part of Vancouver release that we will cover shortly before we go into the servicenow of zero trust exit I just want to go over this slide that covers what service now both really is uh what are the uh the the premium features and products that it covers so far as well so servicenable it is our Marquee security enhancement Suite intended to provide additional layer of security and privacy capability for now platform and it contain consists of five key security elements so far uh number one platform encryption through to an auditor that you're following industry best practices around encryption on off sensitive data and the data privacy show the right data to only the right people by finding classifying and redirecting private information in production and subproduct environment and a zero trust access which is the new product that we're going to go over today granular contextual policies to enforce least privilege access and a Secrets management use item discovery in very sensitive environments with probable assurance that service now employees have zero access to the stored credentials and code signing ensure that the code running on your mid server has not been tempered with and a log expert service automate the collection of real-time the forensic quality logs so you can detect and respond to abuse and misuse faster this comprehensive security solution has been packaged to make it easy for organization to order and consume the solution so this is all what we cover as poldo servicenow of old bundle for next I'll hand it over to Ranbir to go over our main topic which is service net zero trust access with granular level around here back to you thank you so much that was awesome uh hello everyone uh so zero trust is uh a secure is a term that has been prevalent in our security industry for quite some time now and it follows a very basic principle that is uh never trust always verify right and under the zero trust umbrella we cover a lot of things that includes network security continuous monitoring identity governance application security and physical security as well so uh the key tenant that we are focusing as part of the zero trust access product is that uh the the zero trust access principle of providing least privileged access so the idea is that before we provide access to a particular user in a session we need to validate their identity and then we also need to evaluate the trust level of the session now what zero trust says is that if your trust level is not high you should not get all your high privilege roles right so why we are doing it what are the typical use cases so many of our customers uh they have enabled IP restrictions on their instances right so the idea is that if the user who is accessing the servicenow instance is on the corporate Network they would be able to access the instance and if not they don't get to see the instance right however uh with with all the changes that is happening in this world uh with remote workspaces remote workforces uh sprawl of bring your own devices uh that model is not working well for the customers and there is a immediate need of changing that so what is happening is that customers are looking to come out of that restrictive IB Network boundary now with this uh users get a lot of flexibility that they can access the instance from anywhere however this also brings in Risk the administrators are worried that high privilege users they can now access the instance from anywhere using their personal devices they can be on any network and this brings in a lot of uh uncertainty right there could be a possibility that the device is infected there could be the possibility that network is not fully secure right there could be possibility that the device has some compromised uh malwares right so uh one of the requests that we were getting is that can service now do something about the privileged user privileged users right that when they are establishing the session uh can we identify the trust level of that session and then based on the basis of this we do provide some capability to the admin that they can decide whether the user should continue to get the high privilege roles or their privileges should be reduced as per the trust level right so keeping that in mind uh we have built this zero trust access solution and one of the core capability of this feature is that you get a policy framework in that policy framework you can decide what level of privileges user will get based on your conditions of network your conditions related to device locations Etc right so this is a major change so today when you uh access the service now instance uh based on the roles that are assigned to your user and based on the group membership that you have you get the same level of access irrespective of whether you are within the office promises or you are outside at home accessing the instance from your personal device so with this feature now there is a option for the admin to create the granular access level first of all with adaptive authentication they can enforce various security controls to ensure that the right identity is accessing the instance and then with this feature you can also decide that as an admin I don't want to give high privilege roles when let's say user is not on the trusted Network so it definitely improves security posture uh and basically it it protects you again against the threat that are that are typically done for the privileged user personas in some uh in some cases this is also a need from the compliance perspective so if I if I uh take a very common use case right uh it is like let's say user uh you you have a support agent users who have ITIL role so with that ITIL role they can access a lot of things in the servicenow instance right but the title user is also an employee right so the idea is that when the ITIL user is in office right the trust level of the session is high they get to work as a support agent they get all their regular privileges but when the same user is in home uh probably on a vacation or in a home and trying to access the instance on their personal network not connected to the VPN at that time they just get reduced employee roles so they can maybe work on their own tickets uh provide updates on their own created tickets but they cannot see the data of other users so this is this is a new innovation that we are delivering as part of the of Encore release our next slide please okay so how it works so zero trust access uh under the hood uses adaptive authentication policy so if you are not familiar adaptive authentication is an existing product within the servicenow platform Security Group uh what it does is that uh based on certain parameters like network uh location the login method the identity provider attributes it provides you the facility to enforce various security controls so in the left side you are seeing uh the options that are available uh in adaptive authentication policy and on the right side you have outcomes so what you can do with this policy is either you can allow the full access or you can enforce MFA before providing the access to the instance the next thing that you can do is when the access is available you can also decide that whether it's a regular access or a reduced access and in case let's say you are not at all uh comfortable with the risk level of the session you can very well deny the access as well so basically you have this granular control that based on based on your policy you you decide uh what a user can do on the platform and what identity verification steps they have to complete so uh without further Ado uh I'll go through the demo and I will show you this in action uh and the use case that I'm taking today is a very simple use case uh the first one is that I have a user uh her name is Olivia she is an ITIL user and she's an I.T support agent uh and I'm going to configure as a policy to ensure that when Olivia is on the office promises on the customer Network they she will be able to access uh the servicenow instance with her full privileges but when Olivia is accessing the instance from home uh without being on the trusted Network she only gets the base employee role and doesn't get the item rule so this is the use case I am going to cover and show you live in the demo so Focus FMS share my screen sure take over so please let me know if you are able to see my screen yes sure so this is a demo instance uh it's on Vancouver release and in this instance I am logged in as Olivia so you can see that as Olivia is having idle role she has access to the service operations workspace there are incident assigned to her uh and then if she wants she can work on these incident provide updates or close the incident right so uh currently zero trust access has not been enabled on this instance so Olivia whenever she accesses this instance after providing her credentials she will always be able to access the service operations workspace during the demo we will create a policy for a zero trust access policy and enable it in the instance and then we will see that uh when Olivia is not on the trusted Network she is not going to have access to the service operations workspace so I'll log out from this instance and I will log in as a security admin so I have another Persona uh George is a security admin of the Acme car and I'll log in as George so the first thing that I have to do after logging in is that I have to elevate my roles to security admin because zero trust access capability is only available for the security admins I have already installed all the required plugins so after installing the plugin and logging in as a security admin I would simply elevate my privileges to security admin so after elevating my privileges to security admin the uh I'll follow a series of steps so Let's uh Elevate the Privileges so once I Elevate the privilege you will start seeing this red outline that that shows that right now it's an elevated session after elevating my session my use case is that when Olivia is not on the trusted network uh I I need to remove the ITIL role from her session okay so let's first uh Define The Trusted Network so for that you need to Simply go to Adaptive authentication the adapter authentication plugin gets installed uh by default when you install the zero trust access and under adapt to authentication you need to click on the IP filter criteria so in this you can create one or more IP filter criterias and I have already created one so let me open the trusted Network for the Acme core in this IP criteria I have defined a start IP and the end IP so anyone who is logging in from this IB range would be constr would be considered as a trusted Network login okay after defining the trusted Network the next step is uh I need to create an adapter authentication policy so adaptive authentication policy takes two things one is uh I need to add the inputs that I want to use while crafting my condition and the second is using those inputs I I can create one or more conditions and when the condition evalues to true I will associate this adaptive authentication policy to a certain outcome okay so let's go to Adaptive authentication policy again I I can go to Adaptive authentication click on all policies and under which you can see that I have 18 policies today so for this demo purpose I have created one policy already which is remove ITIL role outside trusted Network so uh so first thing that I will do is after creating a policy I will associate policy inputs how do we do that you can click on this edit button and then all the things that you have already configured in this instance uh all the filter criterias would be available here and then you can shuttle them and Associate those inputs to the policy ah as I have already added the trusted Network I'm just going to click on cancel once I have created the edit the filter criteria and the next thing that I will do is creating a policy condition so again I have already created one and the condition is very very simple which simply says that when you uh the condition Vari value to true if the user is not on the trusted Network okay so currently this is simply a policy there is no outcome associated with the policy so this is all existing configuration there is nothing new about it okay now uh I will come to the main focus area that is how do I remove the privileges when a user is not on the trusted Network right so for that I will go to zero trust if you type in zero trust you will get session access role configuration and then I have one policy that that is already created right so let me open the form so this is a very simple form in this form after providing name and description of the policy you need to select the policy that we just created okay so after selecting the policy you need to define the outcome of this policy so there are two actions that are available uh in the zero trust access first one is remove roles uh what it does is that if any condition associated with this policy so conditions are listed here if you can have one or more conditions and if any of the condition evaluates to true the role that you specify in the role list field would be removed from the session okay so this is about the remove rules capability the next capability is the limit to rules so this is another interesting thing so let's say you have large number of Records uh not large number of roles that are assigned to users and you do not want to remove individual roles but what you want to do is you want to limit the access to only a certain role then you can use the limit to role functionality now what will happen in the condition evaluates true is that all the Privileges except the one that is specified in the role list that those will be removed users will get only the privilege that that has been given in the role list what is group list so group list is nothing what let's say if you have again large number of roles and then you don't want to select individual roles and you already have a grouping available you can select uh the group uh here okay we will we will not remove the group membership we will just use the group to uh capture the list of roles that are part of that group okay now uh an important note here is that not only we remove the the role that is selected here we also remove all the child roles that are associated uh with this so you can click here to see what are the different roles that are part of itel so you can see that there are 37 roles and those all 37 roles will be removed from the session if user is on outside the trusted Network okay uh important thing to note the role would be removed or the role will be limited only if the user originally had this role right so let's say there is a use case wherein you don't have the ital role at all let's say you are external user Persona right so there won't be an impact on those user logins so only if the role is already assigned to a user either through the cook membership or through the directoral assignment then only those roles will be removed uh next thing is you admin can create one or more policies uh and then all those policies will be evaluated after the user is logging in after we verify the identity whether it's a single sign-on login or whether it's a local login or ldap authentication after the user's identity has been established we will run all the zero trust access policies that are active in the instance and then on the basis of that we will come up with a list of roles that should be assigned to a user um again one crucial aspect is that we don't remove the roles permanently from this issuer has role table or the group membership table it is all driven through the session what it means is that in this particular session user will have reduced role all the authorization decisions that are going to be made uh when user navigates to let's say one one application to another application one ported to another portal will be made through these session roles uh and if let's say the policy has resulted in reduced role user will see a different level of access when they navigate awesome so what I will do next is after as I have already created this policy uh I will enable the zero plus feature bye uh updating this property so I'll enable the session access property and we will now see the end user experience for Olivia when she is not on the trusted Network so when I Define the type criteria I have kept my current IP Outside The Trusted Network so now if Olivia logs in using the same network she is going to ideally see reduced privileges so let's see this in action so I'll log out from my current security admin session and then I will log in again as Olivia okay so now after verifying the the identity of Olivia zero trust access policies are running and evaluating what level of access should be provided to Olivia in this session because I am an untrusted network uh some of my privileges would be removed now we understand that it might the user experience would be different so what we have done is that we have also ensured that you the end user gets some indication so you can see that there is a info message on top it says that the admin has defined some security policies which are resulting in privilege reduction uh if let's say they want to know more about it they can copy this correlation ID and reach out to the admin so this message is displayed at the time of login this message is also displayed within the plat within the user profile so let's say if you want to see why you don't uh if you are not able to access certain things you can go to a profile section copy the correlation ID and reach to the security admin awesome now let's try one more thing we will try to access service operations workspace so this is the URL for the service operations workspace you can see that because ITIL role has been removed from this session from Olivia she is no more able to access the service operations workspace okay so you can see that uh this is this is a very simple configuration and using this configuration without modifying a single line of code you can define a different level of privileges uh I'll show you some Advanced capabilities uh so this was a very simple use case so let me again login as charge and show you some uh other complex policies so another uh enhancement that we have added as part of zero trustex uh an option to Define policies based on the location so the so in our previous example we have seen that you can define a trusted Network and then on the basis of it you can create policies to produce access you can do on the basis of geolocation of the user as well so what you have to do is you have to go to adapter authentication click on location filter criteria and then you can select a group of countries for which you want to create policies you can uh you can have one or more countries and then this location criteria can be used in existing servicenow adaptive authentication features as well as zero trust access policy so let's say you have a simple use case where you don't want to allow users to access the instance at all from these countries then you can go to servicenow pre-authentication policy use this filter criteria and then you can say that any user accessing the instance from these countries they should be denied okay so this is the location filter criteria uh it's again a very straightforward or nothing very complex about it the second thing uh that I wanted to show you that we covered as part of the the PPT as well is uh you can also use identity provider attribute so what is it so let's say you want to create a policy on the basis of device status okay so typically your identity provider whether it's OCTA or Azure they would definitely have a capability to know whether the devices are trusted or not whether it's a managed device or not and what we can do is that when you are configuring the saml identity provider on the OCTA side uh what you can do is you can send that information as part of saml attributes okay on our side what we can do is that we can read those symbol attributes and then allow the admin to configure policies on those uh attributes so let me quickly show how to do it so for that you need to go to single sign on and you'll existing identity providers so I have already configured OCTA for the demo purposes but it will work for any saml identity provider okay so we have added this new tab uh within the identity provider configuration so basically this tab shows you the attributes that the IDP is sharing at the time of login so you can see we are getting email username and trusted device uh I am interested in creating in a policy based on the device whether it's managed or not whether it's trusted or not right so what I need to Simply do is I need to say I want to use this particular attribute in my adapter authentication policy what it will do now is that it will allow create a filter criteria that can now be added to policies okay so let's see again in an accident I have created a demo policy sorry I have to elevate my role so after elevating my role I'll try to access the session accessible configuration and you can see that I have another policy which is for untrusted devices so again the configuration looks exactly the same what I did is that now I Associated another adaptive authentication policy to this configuration so you can see that I have added two inputs so this input has been created because I said that I want to use that particular saml attribute in my policies how I did it I clicked on edit and all the attributes would be listed here okay so you can see that I have already trusted uh devices status uh criteria here now what is the policy condition here again very simple it says that when user is logging in using the OCTA IDP and if uh OCTA uh saml attribute is saying that the device status is not trusted then this policy condition value value to true and wellness policy conditionally so true I want title user idle role to get removed so again let's see this in action so for this I will login using single sign-on and then we'll see that the roles are getting removed and uh what I will also ensure is that I will deactivate this policy for the demo purpose so I'm I'm deactivating the policy that was based on the trusted Network and right now I only have one policy which is active and that is on the basis of device okay so let me log out again and then this time I will log in with SSO so Olivia will get redirected to Identity provider because I have configured a single sign-on for her after coming to this screen only we will provide her credentials now what will happen here is that uh the identity provider will evaluate whether the device is trusted or not and the same will be sent back to the as part of the saml response the the ZTA framework will read that and then based on the value it will decide whether the role should be removed or it should be kept so in this case again because this device is not a marked as trusted and the identity provider system you can see that my privileges have been removed so uh we have covered three things one is you can how you can create a simple policies based on the network uh conditions like IP condition second we learned about the location filter criteria that can be used with existing adaptive authentication policies and as well as zero trust access policies and third thing is how can we use the identity provider attributes to reduce the rules now this is a very interesting capability that it's not limited to device you can if let's say the identity provider also has capability about the risk score based on various Dynamic parameters they can also send that as part of the saml response attributes and again based on risk score you can create another policy which says let's say risk score is high remove the privileged rolls or limit the rules to very basic employee roles so all those possibilities are there and based on the type of support the Thelma IDP is providing we can configure the policies so this is pretty much for the demo I'll go back to our slides to see if we have any questions there's one question from the show regarding to the policy he's he has like can the policy be applied by assignment groups yes you can do that you can select you may have seen it already on the configuration form you can select the uh the group and then what we will do is we will identify the all the roles that are part of that group and then all those roles will be removed if the condition is evaluated into true oh I see cool thank you please feel free to ask your questions uh if you have any more I will go over the next slide here just a quick recap on what randir just mentioned on the demo he did walk through all the filter uh for zero trust access based on the the geolocation the network device as well as the identity provider attributes as well so I will go over the next slide here so if you're not subscribed to our uh platform privacy apart from privacy and Security Academy section please feel free to subscribe to our Channel we're going to be we had a few roughly around like seven to eight different Academy sessions around all different topics in within the Vault bundle that starts from overall what service now both really is and then we had a platform encryption and some other components as well so feel free to watch those on YouTube as well and if you haven't subscribed feel free to just scan this QR code and it will be directed to that page as well and what's available for us this is both the internal and external so we have social media platform we have YouTube channel and Linkedin as well as Instagram podcast as well so simply you can just skip scan this QR code or just type servicenow on that channel as well and we have a documentation site where you can see all the the new enhancement and and features that is coming as part of Vancouver release as well as previous releases too and most importantly we have a community site which is python privacy and security Community set generically to service that Community set as well so what you can do is just you skip uh you can read all the different documentations and podcasts as well as some of the articles that is recently published regarding to all the different use cases and product and features as well so with that I would like to recap further questions if you have any more questions regarding to servicenow zero trust access that'll be released as part of Vancouver release in September and which will be part of servicenow volt bundle and please again make your purchasing decision based on the product that it exists today so we still have some time for Vancouver release so it's not released yet but uh rendier just went over some of the highlights through this demo as well so I'm just going to stay two more minutes to see if there's any questions or not otherwise we will wrap up run there anything that you would like to add yeah so one of the important thing that I want to add is that uh the zero trust session access policies those are applicable to web sessions uh and if let's say you have parallely running two sessions one is with a reduced trust label and one with uh with the normal trust label you would see different level of access in both of these two sessions so that's the Merit of this feature that it's totally dynamic in nature and all the Privileges are within the session so a high risk session will have low privileges low risk session and high trust level session with heavier regular couplages it never elevates any role uh it always keep your normal access or reduced access based on the conditions that are created in the policies is configurable if if you want to show some different message you can change it uh all these uh session access records are kept for 30 days for logging audit and logging purposes so you can also verify that which policy was applicable what role have been removed from particular user session oh I don't see any questions coming right now but if you have any more questions feel free to ask through our platform uh privacy and security community site by posting your questions we'd be happy to answer your questions as well once again thank you so much render for joining in and speaking through all the uh the new enhancement around zero trust access which is coming as part of Vancouver release and I thank you all for joining this session as well till next time stay tuned bye
https://www.youtube.com/watch?v=ChdQkn55gPs