Account validity recertification policy is to certify whether an account should exist or not. For example, in a company there may be employees access recertification or review yearly. For the recertification, an audit is created, which generates business requests that are sent for approval. The engine bundles the recertification items into business requests as per the responsible party. For any item being recertified where its responsible party is null, it bundles them all into one business request where the subject of the request is the fall-back assignee. Recertification policies are policies that you add to audits to generate recertification review tasks for the access assignments given to people, roles, groups, and query-based collections.
Account validity recertification policy is to certify whether an account should exist or not. Possible decisions are generally available as certify, disable and delete. However, these possible decisions are configurable. For configuring them we need to take the following steps.
Log in to the EmpowerID web application
On the navbar, expand IT Shop and select Approval Flow Policies.
On the Approval Flow Policies page, select the Item Type Actions tab.
Then search for Recertify Account Validity.
Click on the Recertify Account Validity and scroll down to select Decisions for Approval Flow Steps.
Click on the + icon to add more approval decision if needed.
In this post, we will create account validity type recertification policy and add a target to it.
Pre-requisite for recertification policies, audit compilation and fulfilment of business requests.
Create a Account Validity Type Recertification Policy
Log in to the EmpowerID web application as an auditor or other person with the ability to configure audits.
On the navbar, expand Compliance and select Recertification.
On the Recertification page, select the Recertification Policies tab.
Then click + icon to create a new Recertification Policy
The policy details page opens up.
Select policy type as ‘Account Validity.’ Enter any name, display name, and description.
Click on Save.
Add the target type “Location” to the policy createdClick on the '+' icon at the bottom of the policy details page to add the target.
The attestation policy target section opens up.
Under the type dropdown, select ‘Location.’
Under the select a location dropdown, search for a location and select it.
Click on Save.
Add the target type “Set Group” to the policy createdClick on the '+' icon at the bottom of the policy details page to add the target.
The attestation policy target section opens up.
Under the type dropdown, select ‘Set Group.’
Type a query name under “enter a query-based collection name”.
Click on Save.
The account validity policy type with two target types are created.