Access Control List Rules | Vancouver Release Platform Security Demo
foreign and I'm a technical consultant here at glidefest today I'm going to show you a new feature that servicenow is going to offer with the Vancouver release and it revolves around working with security rules or better known as ACLs I will try to explain you the new feature with an example of a use case so taking any incident here as an example I have added a custom field called business unit to the form and it is a simple string field as part of the use case we want only admins or users with the admin role to be able to write on the business unit field now usually in order to complete this requirement I would have gone to config security rules or config all and then security rules and created a new write ACLs where I would only allow admins to be able to write on the business unit field with the Vancouver release it's a lot simple so again I'll start with elevating myself to security admin once elevated if I right click on the business unit field in addition to the typical options I get an option called configure security here I can simply click on this option on the pop-up here you will see that the definition is for the incident table and the business unit field operation for our use case we are going to pick right and you will see we have all the available roles on the left hand side all we need to do is pick the role that we want the right access given for the business unit field so I'm simply going to click on admin and hit OK once it is saved I can close the Box and let me reload and that was pretty much all for testing I'm going to impersonate the ITIL user as an ideal user if I open any incident you will see the business unit field for me is read only because given that I do not have the admin role I do not have the access to write on the business unit field how simple was that if an impersonation and go back to the incident record I'm going to elevate myself again to the security admin if I show you the dictionary configuration for the field you'll notice an ACL for the right operation has already been created and it was done through the configuration that we just did so we really didn't have to go ahead and create a new record all you had to do is right click hit configure security and pick the correct role now I'm expanding on this let's suppose we also want to give a particular group access to right on the field as well so right from here I'm just going to click on new to create a new ACL for operation again I'm going to pick rate incident business unit down below you will see a new section called security attribute condition we already had a place for roles as well as to add conditions and a script but now what we have is the security attribute conditions you can take from the following options so I can pick group is and for the demo I'm going to pick ID securities and just going to save this and that was on ID security group members should now be able to write on the business unit field typically I would have written a script something like the login user is member of the it Securities team but as you can see it is much simpler this way you can also pick the other options as using fit for your use case group explicit means that the logged in user or the user performing the operation needs to be directly given membership to the group so they can as part of the first option they can be part of a parent group of the ID Securities group and they will still have the access to write on the field with re-changing it to group explicit only the members that are included in the ID security team would be able to edit or write on the field has admin rule pretty self-explanatory impersonating so if the login user or the user performing the operation is impersonating a certain user or if they are impersonating is true or false if the session is Interactive if the user is logged in or not rule again we can expand on this and role explicit again the same meaning as I explained for the groups so for role they can inherit the role as a child role to an apparent role for example they can have a cmdp read role if they have the idle role but if we pick the role explicit they need to have the cmdb writer in order to perform the function or the operation that was all for the demo today I hope this was valuable and I'm pretty sure this is going to help us a lot in order to create ACLS or work around vcls and it's going to make our life a lot more easier [Music] thank you [Music]
https://www.youtube.com/watch?v=MfM823fBuGc