New Capability: Machine Identity Access Requests

Description

We are pleased to announce the release of Access Requests for Machine Identities.

With this release, Machine Identity Security (MIS) customers can now enable their users to request access to Machine Identities. When this feature is enabled, the option to request access on behalf of Machine Identities becomes available to users of the Identity Security Cloud (ISC) Request Center.

Machine Identity Access Request Overview

In this release, access requests for Machine Identities is available for entitlements only. The ability to request roles and access profiles for Machine Identities will be supported in a future release.

Entitlements may only be requested from sources where the selected machine identities already have one or more accounts. The ability to to create accounts on-demand will be supported in a future release.

If a Machine Identity has multiple accounts on a source, the requester will be required to select the target account for provisioning.

Approval for Machine Identity access requests is determined by the access request configuration for each entitlement. However, in the case where a manager is assigned as the approver, the approval is routed to the Machine Identity owner.

Machine Identity Screenshots

Machine Identity Access Request

Machine Identity Entitlement Selection

Machine Identity Review Request

Who is affected?

This is being rolled out to all Machine Identity Security customers.

Important Dates

Sandbox rollout: week of Jul 24, 2026

Production rollout: week of Aug 04, 2026

2 Likes

Is this available via API call?

@mcheek Looks like you can just use the existing access request endpoint:

1 Like

Do you have to specify the account selection stuff and whatnot? Or is that just because that particular identity has multiple accounts in that source?

I just did this in the UI first and then stole the request body and then tried it against the API endpoint. So no you probably do not need all of that information.