Identity Governance and Administration (IGA) is a service that allows your enterprise to obtain data for audit trail and certification, and helps Organization Owner users to manage self-service access requests, approvals, violations, and API tokens in real time in Omnissa Cloud Services.
The IGA service comes with two sets of features: basic and advanced. It is only available to Organizations with federated domains.
To start using the basic IGA features, an Organization Owner must activate the IGA service by clicking the Get Started link on the Identity & Access Management > Governance page.
Using the IGA service in an Organization, lets Omnissa Cloud Services users do the following:
| As an | with basic IGA | with advanced IGA |
|---|---|---|
| Organization Owner user | - Access the IGA dashboard from the Identity & Access Management > Governance page in the Cloud Services Console. - Activate or deactivate your Organization Members ability to submit self-service requests for additional roles. - Govern access to services in your Organization by managing incoming Organization and service role requests. - Monitor violations and immediately respond to threats. | Onboard a service in any governance activated Organization linked to your corporate identity provider. |
| Organization Member | If activated in the Organization, submit self-service access requests for additional Organization and service roles. | Onboard yourself in any governance activated Organization linked to your corporate identity provider. |
How do I activate advanced Identity Governance and Administration in my Organization
If your domain is federated, additional Advanced Identity Governance and Administration (IGA) features can be activated for all Organizations in the federated domain.
Activating the advanced IGA features in your Organization requires the following:
- An Organization Owner from the federated domain must link your corporate identity provider to Omnissa Cloud Services.
- An Enterprise Administrator must activate the advanced IGA features for some or all Omnissa Cloud Services Organizations that are linked to their corporate Identity Provider.
When advanced IGA features are activated, non-Organization users can request Organization and service roles access in linked Organizations during onboarding.
How do I manage self-service requests for additional roles
As an Organization Owner user of an Identity Governance and Administration (IGA) activated Organization, you manage Organization and service roles requests through the Governance > Requests page in Cloud Services Console.
The option to submit self-service requests is available to Organization Member users only if this option is activated in your Organization.
| If request for additional roles is activated, Organization Member users request access by... | If request for additional roles is not activated... |
|---|---|
| clicking the Request Access link on a service tile in the Cloud Services catalog. | the Request Access link in the service tile is not clickable. |
| clicking the Request Roles link on the My Account > My Roles page. | the Request Roles link is not displayed on the My Account > My Roles page. |
How do I activate or deactivate self-service requests
To activate or deactivate self-service requests for additional roles in your Organization, follow the listed procedure.
- Go to Governance > Requests and click Settings.
- Click the Request for additional roles slider to either activate or deactivate the setting.
- Click Save.
How do I process pending requests?
All incoming requests for Organization and service role access are listed in the Pending Requests section. The Past Requests lets you view historical data for all requests created in your Organization.
To approve or deny requests, select one or several entries in the Pending Requests list and click the respective button. The users requesting the role access receive an email notification when their request is approved or denied.
Can I modify access requests before I approve them?
As an Organization Owner, you can modify the time period for service role access requested by an Organization Member. You view the time period of the original request by clicking the Request ID link. To change the requested time period, click Approve, then select Approve with modification. Change the setting and submit the change you made.
Note: The Approve with modification option is available only for service role access requests and is not applicable for Organization roles.
Organization Owners cannot modify the service or role access originally requested by the Organization Member. If you want to provide guidance to the requester about the proper level of access you are willing to approve, you have the option to include a message when denying their request. The requester receives an email notification and can submit a new access request with the appropriate Organization and service roles.
How do I monitor violations of policies in my Organization
As an Organization Owner user in an Identity Governance and Administration (IGA) activated Organization, you monitor access violations for user logins and logins with OAuth apps and API tokens in your Organization. You define and modify the policies for triggering violations.
You set up violation policies for logins in your IGA-activated Organization by activating various triggers for OAuth apps and API tokens, such as inactive API tokens, inactive OAuth owners, broad service scopes, insecure or unapproved URIs for OAuth apps.
Note: If Source Domain authentication policy is activated, User Access violations are captured for all login attempts originating from domains that are not allowed by the policy setting.
Procedure
- Log in to the Cloud Services Console with your corporate account.
- Navigate to Identity & Access Management > Governance > Violations.
- Click Settings.
- In the Violation Settings page that opens, modify the settings for OAuth Apps and API tokens as appropriate.
- Click Save.
Results
The Violations dashboard is refreshed to display violations according to the new settings.
The information on the dashboards is updated daily.
How do I take action against violations of policies in my Organization
As an Organization Owner user in an Identity Governance and Administration (IGA) activated Organization that monitors violations, you can take action against the violations discovered in your Organization. You access the full list of violations by navigating to Identity & Access Management > Governance > Violations.
The violations captured in your Organization are grouped by the type of authentication method used to log in to Omnissa Cloud Services that triggered the violation. Click on the respective tab to view the full list and possible actions you can take to respond to a violation.
- The Violations > OAuth Apps tab displays the name of the app that triggered the violation, its severity, description, and email of the Organization user who created the OAuth app.
- The API Tokens tab displays the name of the API token that triggered the violation, its severity, description, and the email of the Organization user who created the API token.
- The Violations > User Access tab displays the email of the Organization user whose login attempt triggered the violation, its severity, the date the violation took place, and the source domain from which it occurred. A user access violation is captured for login attempts from any domain that is not allowed by the Source Domain authentication policy.
The following table describes the actions you can take in response to violations in your Organization.
| To... | Do the following... |
|---|---|
| Change the visibility of a violation | This action changes the visibility status of a violation from Active to Hidden. It does not delete the violation and can be reverted. 1. Locate the violation you want to hide and click its corresponding double arrow to expand its details. 2. Select the check box next to the active violation you want to hide. 3. Click Hide. The violation is no longer displayed in the details section. |
| Display a violation that has been hidden | This action displays violations with Hidden status. Expand a violation's details section and switch on the Display All toggle. All violations that have been hidden are displayed. |
| Remove an OAuth app from your Organization | This action removes the OAuth app and blocks it from accessing the Organization. The OAuth app is not deleted, yet no further violations will be reported from this app. The removal action cannot be reverted from the Violations page – to monitor violations from this OAuth app it has to be added to the Organization again. 1. On the Violations page, open the OAuth Apps tab. 2. Locate the app you want to remove. 3. Select the check box next to its name. 4. Click Remove. |
| Edit the severity of a violation | Based on your Organization's needs, you can define the severity for any violation criterion. 1. On the Violations page, click Settings. 2. Use the Severity drop-down menu to change the setting for each violation criterion you want to modify. 3. Click Save. |
How do I manage API tokens in my Organization
As an Organization Owner user in an Identity Governance and Administration (IGA) activated Organization, you monitor the API tokens created in your Organization and set constraints for idle and maximum Time to live (TTL) for all newly created tokens.
To access the API Tokens dashboard, open the Cloud Services Console and navigate to Identity & Access Management > Governance > API Tokens tab. The dashboard that opens gives you a list of all API tokens created by users in your Organization.
For each API token, you can view details, such as token name, name of the Organization user who created the API token, creation and expiration dates, the date the token was last used, and the scopes of the token – the Organization roles assigned to the token.
The API Tokens dashboard list displays an alert icon (Alert icon) if the TTL policies for your Organization have been violated. The TTL policies set for your Organization apply to all new API tokens created by the users in your Organization. If you change a TTL policy, an alert icon will appear next to all previously created API tokens which are violating the new setting.
There are two TTL policy settings you can activate, deactivate or modify:
- Idle Token TTL: This setting defines what is the allowed idle Time to live for an API token before it violates the policy.
- Max Token TTL: This setting defines what is the maximum allowed Time to live for any API token created in your Organization. Organization users will not be able to generate API tokens with a Max Token TTL greater than the one defined by this setting.
What can I do if an API token violates any policy or guideline in the Organization
If an API token violates a TTL policy in your Organization or in any way looks suspicions to you, you can deactivate the token from the API Tokens dashboard. This way it cannot be used to access the resources in the Organization.
- On the API Tokens dashboard, select the API token you want to deactivate.
- Click the Deactivate link.
The API token status changes from Activated to Deactivated. The owner of the API token receives an email notification from Omnissa Cloud Services that a token they've been using to access the Organization has been deactivated by an Organization Owner. - To reactivate an API token that has been deactivated, select the API token on the dashboard, then click the Activate link. The owner of the API token receives an email notification confirming the reactivation.
How do I change the TTL policies for API tokens in my Organization
To modify the API tokens TTL policies, do the following:
- On the API Tokens dashboard, Identity & Access Management > Governance > API Tokens tab, click Settings.
- To activate or deactivate a policy: Use the Policy status slider.
- To change a TTL setting: Enter a new value in the respective TTL setting section and select a time unit from the drop-down list. The time unit can be minutes, hours, or days.
- Click Save.
Validation runs of existing tokens against the policies take place once in 24 hours. This means it may take some time before the API Tokens dashboard list of violations gets updated as a result of the change you made.
How do I assign default roles in my Organization
As an Organization Owner user in an Identity and Access Governance (IGA) activated Organization, you can assign default Organization and service roles to users in your Organization by setting up a policy.
The default roles granted through that policy apply to all users logging in the Organization from a specified federated domain and cannot be edited at the user level. To change the default role entitlements, you must modify the policy.
Important: There is a known issue that as an Organization Owner, you cannot view the users in your Organization who have been granted default roles based on the policy and who have no other roles in the Organization. These users will not display on the Active Users list in Cloud Services Console unless they request additional roles and the requests are approved. Once users with default roles obtain additional roles in the Organization, they appear on the Active Users list and as an Organization Owner, you can grant them additional roles.
Prerequisites
- Your corporate identity provider is linked to Omnissa Cloud Services.
- Advanced IGA features are activated in the Organization.
- You have an Organization Owner role in the Organization.
Procedure
- Log in to the Cloud Services Console with your corporate account.
- Navigate to Identity & Access Management > Governance > Requests.
- Click Settings.
- In the Grant Default Roles section of the page, click the Add Domain Policy link.
- Enter a name and description for the new policy.
- Select the domain to which you want to apply the policy.
- Select the Organization and service roles that you want to automatically assign to all users logging into your Organization from the specified domain.
- Click Save.
Results
The roles you specified become available to all users from the specified domain upon their login to Omnissa Cloud Services.
Was this page helpful?