Machine Identity Security Overview
SailPoint Machine Identity Security helps organizations achieve comprehensive governance, compliance, and security outcomes related to machine accounts.
Machine Identity Security helps you:
-
Discover and classify machine accounts on a source.
-
Correlate machine accounts to an application identity.
-
Certify application identities and their access.
-
View and manage machine accounts for all sources.
To discover, classify, and manage machine accounts, users must be an Org Admin, Source Admin, or Source Sub-Admin who is a member of the source's governance group. Users identified as account owners may review application identities and their access in certifications.
Implementing Machine Identity Security
Your implementation process depends on the data available to your organization. For example, if your organization stores application data in a database, you can begin by using this data to create application identities. Organizations that do not maintain application data can create application identities at a later stage.
Choose your next step based on your configuration
If your organization stores application data in a database, SailPoint recommends following this implementation process:
-
Configure sources that contain machine accounts.
-
Aggregate the machine accounts that require governance.
-
Create application identities to group machine accounts with their associated program or service.
-
Create machine account subtypes to classify existing and future machine accounts by their type and function.
-
Set criteria to determine which source accounts should be classified as machine accounts.
-
Map available account attributes to assign account owners and correlate machine accounts to a machine identity.
-
Review and update machine accounts and their attributes.
-
Create a machine account certification campaign to verify access items for application identities.
-
Certify machine identities and their access.
If your organization does not maintain application data, SailPoint recommends following this implementation process:
-
Configure sources that contain machine accounts.
-
Aggregate the machine accounts that require governance.
-
Create machine account subtypes to classify existing and future machine accounts by their type and function.
-
Set criteria to determine which source accounts should be classified as machine accounts.
-
Review and update machine accounts and their attributes.
-
Certify uncorrelated machine identities and their access.
-
Create application identities to group machine accounts with their associated application or service.
Documentation Feedback
Feedback is provided as an informational resource only and does not form part of SailPoint’s official product documentation. SailPoint does not warrant or make any guarantees about the feedback (including without limitation as to its accuracy, relevance, or reliability). All feedback is subject to the terms set forth at https://developer.sailpoint.com/discuss/tos.