Access request for machine accounts

Hello,

Today, we are able to create a machine account by assigning an entitlement during creation, or not.

However, I’m not sure whether it is possible to provision additional access from IdentityNow afterward. I’m unable to see either the machine account or the machine identity in the Request Center.

Thanks.

Hello, Fatima. Your understanding is correct.

The machine account flow supports selecting entitlements during creation, but I don’t see a Request Center option today to pick an already created machine account or machine identity and request additional entitlements for it afterwards.

So the supported flow right now is:

  1. Make the needed entitlements requestable.

  2. Select them during the Create Machine Account request.

  3. After provisioning, use ISC to track and govern that access on the machine account or machine identity side.

For additional access after the machine account already exists, I would not try to force it through a normal user access request, since that flow is still identity/user based.

I also saw that you already asked this same point in the New Capability: Machine Account Creation product thread, so I think it is worth waiting for Natalia/product team to confirm the official supported path. Based on what is documented today, I would treat this as a current product gap and handle the access change directly on the target source side, then re-aggregate so ISC picks up the updated access for visibility and governance.

Hello @fatimahm As you know Creation of Machine Account is a new feature added by the SailPoint Team. you can follow the new published documentation:

Thank you. Nathalie confirmed that the ability to request access for existing machine identities via the Request Center is on SP near-term roadmap :crossed_fingers: