logo

NJP

Page not found

Zero Trust Access | Dynamically control access privileges

Import · Sep 20, 2023 · video

This video shows how to use ServiceNow
Zero Trust Access to dynamically control access privileges for user sessions in a ServiceNow instance. This gives security administrators
better control over users access. During the session login process, ServiceNow
Adaptive Authentication uses multiple criteria to limit a user's access
privileges. Adding Zero Trust Access expands
your authentication capabilities by adding the user's location
and authentication attributes from your identity provider
to the input criteria. Zero Trust Access also adds the ability
to reduce users access to the instance by removing specific rules
based on their authentication criteria, rather than simply granting
or denying full access. To configure user access using Zero Trust Access, we're logged in with the admin role. Now we'll elevate our role
to security_admin. We’ll navigate to Zero Trust Access, Session Access Role Configuration. Each configuration contains
an access policy, along with an action to perform
if the policy evaluates to true. We’ll open this configuration, “Remove ITIL role outside trusted network.” Here is our access policy. We then open the record
and see our Policy Input, trusted Network and view our policy condition
outside the trusted Network. When we open the condition,
we see that it's true. If the Trusted Network input is false. Or we can say if the user's IP
address is outside the range defined for our trusted network,
the policy evaluates to true. If the policy is true, we can take one of two actions to limit
the user's access. We can remove
specific roles from the user. Or we can limit
the user to specific roles. If we choose remove rules zero Trust
access removes the rules in this list - in this case,
the ITIL role. Zero Trust Access also removes all the child roles for the roles in the list. You can check the child roles here. If the user does “not” have the role to be removed but “does” have a child role, Zero Trust Access removes the child role. If we choose “Limit To Roles,” Zero Trust Access limits the user to “only” the roles in the list. That is, Zero Trust Access takes away all the roles the user may have, along with all of their child roles, “except” for the roles in the list. Zero Trust Access does not add any roles that the user doesn’t already have. For this configuration, we want to “remove” the ITIL role. To use Zero Trust Access, we also need to set a few system properties. To enable Zero Trust Access, we’ll select Enable Session Access. We’ll also enable logging to help debug Zero Trust Access issues. The “preference” property determines whether the Remove or Limit action takes precedence. If a particular role appears in both a Remove action and a Limit action to be taken at the same time, this property determines which action Zero Trust Access will take. Here we’ll “remove” the role. The “audit data” property determines how long the system retains session access data before deleting it. The “information to be displayed” property specifies the message users see whenever Zero Trust Access removes any of their roles. When a user logs in, they’ll see this message, along with the session ID. This message also appears in the user’s profile, so they can always find the session ID any time after they log in. As a security admin, you can click Session Access Audit to view additional information. Here we can check the session access data and look up the session ID to find the Zero Trust Access policies that were applied for the session. We can also view the Remove or Limit actions that were taken and other information. That completes the setup. By reducing users’ roles when they log in, under conditions you define, Zero Trust Access gives you better control
of their access to your instance. For more information, see our product documentation or knowledge base. Or ask a question in the ServiceNow Community.

View original source

https://www.youtube.com/watch?v=NYQ8g4uw12U