The management role access assignment recertification process validates whether the access granted to a management role is still required for a valid business purpose. Certain actions must be made if access is no longer required. In other words, the management role of access recertification policy is to certify whether access granted should exist or not.
For the recertification, a recertification policy is created, a recertification audit is created, the recertification policy is added to the audit, then the audit is compiled, which generates business requests that are sent for approval.
The engine bundles the recertification items into business requests based on the object itself. Therefore in this case the management role is the bundle for the business request and the access already granted are items.
Note: For the recertification to work in EmpowerID, certain prerequisites must exist.
Create a Management Role Access Assignment Recertification Policy
Log in to the EmpowerID Web application as an auditor or other person with the ability to configure audits.
On the navbar, expand Compliance and select Recertification.
On the Recertification page, select the Recertification Policies tab
Then click + icon to create a new Recertification Policy
The policy details page opens up.
Select policy type as ‘Management Role Membership.’
Enter any name, display name, and description.
Click on save. The recertification policy is saved successfully.
Add the target type “management role” to the policy created
Click on the '+' icon to add the target.
The attestation policy target section opens up.
Under the type dropdown, select ‘Management Role.’ Enter the name of the Management role
Click on Save.
Add the target type “location” to the policy created
Click on the '+' icon to add the target
The attestation policy target section opens up.
Under the type dropdown, select ‘Location.’
Click on Save
Add the target type “Management Role Definition” to the policy created
Click on the '+' icon to add the target
The attestation policy target section opens up.
Under the type dropdown, select ‘Management Role Definition.’
Click on Save.
Add the target type “Set Group” to the policy created
Click on the '+' icon to add the target
The attestation policy target section opens up.
Under the type dropdown, select ‘Set Group.’
Click on Save.'
Add multiple targets to the policy type “Management Role Access Assignment.”
Click on the '+' icon to add the target
The attestation policy target section opens up.
Under the type dropdown, select ‘Set Group.’
Click on Save.
Click on the '+' icon to add the target
The attestation policy target section opens up.
Under the type dropdown, select ‘Management Role Definition.’
Click on Save.