Enhancement
Non-Employee Risk Management Users Connector - Automatic Synchronization
Description
The Non-Employee Risk Management team is pleased to announce updates to the Non-Employee Risk Management Users connector that will allow synchronization of users and user roles with Identity Security Cloud accounts and entitlements without needing to wait for periodic aggregations. Additionally, NERM admin users can now assign roles directly to users in the Non-Employee Risk Management Admin UI.
Problem
-
NERM user and user role data and ISC account and entitlement data are kept consistent today through periodic aggregation. Any addition or change made in NERM is reflected in ISC only after the next successful aggregation, so there is a predictable delay between when an update is made and when data matches in both systems.
-
NERM admins couldn’t assign roles directly to users within the Non-Employee Risk Management UI. This capability is available via API, but supporting it via the NERM UI allows implementers to easily set up access during implementation.
Solution
New toggle for user and role sync with Identity Security Cloud
-
We’ve added a new USERS tab to the Identity Security Cloud Connection Settings page in Admin > System. This new tab has a toggle labeled “Sync with Identity Security Cloud” and a Source ID field.
-
Toggle Default: Disabled
-
Who can enable the toggle:
-
Customers with an established source created with the NERM Users connector
-
Customers that haven’t yet created source with the NERM Users connector
-
-
What happens when initially enabled:
-
When the toggle set to ON, if NERM detects a NERM Users connector source, the Source ID will default and the user only needs to click Save to complete enablement.
-
When the toggle set to ON, if NERM does not detect a NERM Users connector source, a toggle will display asking the user if they want NERM to create a source or if they want to manually create one and then update the Source ID in NERM once that is completed.
- When NERM creates the source, Connectivity Details, User Account Schema, and Entitlement Schema are populated, and any further configuration must be completed by an ISC Admin.
-
-
Toggle = ON behavior: For sources created with the Users connector, when a change is made to a user or role in NERM, a single account aggregation or an entitlement aggregation is immediately initiated to update ISC.
-
Toggle = OFF behavior: For sources created with the Users connector, NERM user/role data and Identity Security Cloud account/entitlement data will sync via periodic aggregation.
-
This new toggle has no dependency on the settings and fields in the Non-Employee and Assignment tabs of the Identity Security Cloud Connection Settings.
Toggle = OFF
Toggle = ON with Source ID Populated
Source ID
Identity Security Cloud Connection Settings > Create New Source Modal
Role assignment via NERM Admin UI
- We’ve enhanced the NERM Admin UI to allow admins to assign and unassign users to roles. The ability to perform this action via API remains unchanged.
Admin > Lifecycle > User Roles
Who is affected?
-
NERM + ISC customers who are already utilizing the Users connector and managing NERM Users and User Roles directly in ISC.
-
NERM + ISC customers who want to utilize the Users connector and managing NERM Users and User Roles directly in ISC.
Action required
- There is no immediate customer action needed. Use of the new synchronization toggle is not required, and it’s disabled by default.
Important dates
Production rollout: Available now
Resources
-
Documentation: Managing User Accounts in Identity Security Cloud - SailPoint Non-Employee Risk Management Admin Help
-
Previous User connector-related announcements:




