Hello, Fatima. Your understanding is correct.
The machine account flow supports selecting entitlements during creation, but I don’t see a Request Center option today to pick an already created machine account or machine identity and request additional entitlements for it afterwards.
So the supported flow right now is:
-
Make the needed entitlements requestable.
-
Select them during the Create Machine Account request.
-
After provisioning, use ISC to track and govern that access on the machine account or machine identity side.
For additional access after the machine account already exists, I would not try to force it through a normal user access request, since that flow is still identity/user based.
I also saw that you already asked this same point in the New Capability: Machine Account Creation product thread, so I think it is worth waiting for Natalia/product team to confirm the official supported path. Based on what is documented today, I would treat this as a current product gap and handle the access change directly on the target source side, then re-aggregate so ISC picks up the updated access for visibility and governance.