In order to better support authentication and access management via Identity Security Cloud, Non-Employee Risk Management will soon make some changes to User Accounts for ISC-connected tenants.
Why are these updates being made?
We will soon be enabling the Non-Employee Risk Management Users Connector in Identity Security Cloud, which will allow customers to manage their NERM Lifecycle user accounts and access via established ISC lifecycle and governance processes. This is being designed to replace the current approach, where NERM Lifecycle user access is managed via LDAP Directory groups.
In order to ensure that NERM Users will have the correct access on their accounts when customers make the change to leveraging the new connector, we need to ensure that the Users in NERM can be properly associated to a single identity in ISC. These changes will automate that association.
Which customers will be affected?
Any Identity Security Cloud + Non-Employee Risk Management customers who leverage Identity Security Cloud for authentication.
What updates are being made?
Lifecycle User Deduplication
In the past, it was possible for duplicate user accounts to be created in NERM in cases where the same users would authenticate through ISC using a local login (name and password) as well as using their Identity Provider (IDP).
For customers who have these duplicate user accounts, Non-Employee Risk Management will be consolidating these users under the same account. These accounts will be consolidated using the SailPoint Identity ID attribute, which is present on all Lifecycle user accounts in NERM and will always correspond to a single ISC identity.
Lifecycle User Attribute updates
Currently, lifecycle Users in NERM are created based on the data received from the Identity Provider. Their values of their user attributes in NERM, such as login, name, and email,will correspond to the values of these attributes that are received from the SAML claims from the IDP.
Going forward, the values for login, name, and email will correspond to the values for the Identity Attributes on the NERM users’ Identities in ISC.
| ISC Identity Attribute | NERM User Attribute |
|---|---|
| Display Name | Name |
| Work Email | |
| username | login |
How will NERM Lifecycle users be affected by these changes?
We anticipate the effects to be minimal.
What is staying the same
-
NERM Lifecycle users will not need to sign out.
-
NERM Lifecycle users will retain their existing access.
-
NERM Lifecycle users will continue to authenticate as normal.
-
New NERM Lifecycle users can be created as normal.
What is changing
-
User Account Consolidation: Duplicate accounts created via local authentication (when the primary account is managed through IDP) will be removed. This will not affect user access, as only redundant accounts are being deleted.
-
Attribute Updates: After the change, user attributes in NERM (such as display name and email) will be updated to match the information in ISC. This will happen when users authenticate. Users who do not log in will not see immediate changes until their next authentication.
What do you need to do?
-
Review ISC Identity Data: Please review the identity data within your ISC tenant to anticipate potential changes to user attributes (display name, email) in NERM.
-
Inform Users: Let your users know that their display names and/or email addresses in NERM might be updated to reflect the information in ISC.
When will these changes go into effect?
-
Dev/Sandbox:
Monday, November 10- Lifecycle User Deduplication: Complete
- Lifecycle User Attribute updates: Tuesday, November 18
-
Production:
Monday, November 17- Lifecycle User Deduplication: Monday, December 1
- Lifecycle User Attribute updates: Monday, December 1