New Capability: Privilege Classification in Identity Security Cloud

Hi Kelly,

The value field is multi-value, so you need to hit enter after entering each value in the input box. It will then appear as a little chip underneath the row. You can add upto 50 values.

More info here: Managing Privilege Classification - SailPoint Identity Services.

Regards

Kev/.

1 Like

Kev, this update is a bit of a pain point for us as we use the Privileged marker to build out a lot of our campaigns and with updates to some sources in which we had to wipe out entitlements and re-aggregate we completely lost the pre-marked Privileged flag.

As I have ~ 700-800 entitlements to update across about a dozen sources is there an easy scripted way to do this or a bulk way to update source entitlements? Previously this could be done via the UI by going into the source, downloading the Entitlements CSV and switching the Privileged flag from False to True and then re-uploading the csv but that no longer works and it doesn’t appear that there is a simple or scripted way to iterate through a large number of entitlements to set the flag to High/Medium/Low, rather you have to do it in batches of 50 via the API.

Hi Ryan,

We have some updates planned for Privilege Discovery & Classification and the ability to export/import direct privilege levels using csv files is being worked on now.

In the interim, you could use the criteria to setup lists of entitlements names to match and set to high/medium/low, as well as potentially some pattern matching i.e. ā€˜admin’, ā€˜approver’ etc.

Once we have a firm time line on the csv export/import updates I’ll let you know.

Regards

Kev/.

Hi Kelly,

Just wanted to let you know, based on yours and other customer feedback, we are making a change to this UI to make it clearer to know how to add values to the multi-value list.

Thank you for your feedback,

Regards

Kev/.

1 Like