<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Use Cases Archives - SecurEnds</title>
	<atom:link href="https://www.securends.com/documentation-category/use-cases/feed/" rel="self" type="application/rss+xml" />
	<link>https://www.securends.com/documentation-category/use-cases/</link>
	<description>SecurEnds - User Access / Entitlement Reviews, Identity Access Management, Cloud Access Management, Identity Governance, IGA, IAM</description>
	<lastBuildDate>Thu, 27 Feb 2025 10:12:20 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	

<image>
	<url>https://www.securends.com/wp-content/uploads/2022/02/cropped-se-favicon-new-32x32.png</url>
	<title>Use Cases Archives - SecurEnds</title>
	<link>https://www.securends.com/documentation-category/use-cases/</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>Campaign Delegations</title>
		<link>https://www.securends.com/documentation/campaign-delegations/</link>
					<comments>https://www.securends.com/documentation/campaign-delegations/#respond</comments>
		
		<dc:creator><![CDATA[secure]]></dc:creator>
		<pubDate>Fri, 07 May 2021 21:35:04 +0000</pubDate>
				<guid isPermaLink="false">https://www.securends.com/?post_type=docs&#038;p=8468</guid>

					<description><![CDATA[<p>Campaigns can be customized further using Delegations. There are two types of delegations: People Delegations and Credential Delegations. Each delegation has a different function and resulting use case. Delegation settings can be found in the &#8220;Delegation&#8221; tab under Access Review on the left hand menu. Initiating a People Delegation Clicking &#8220;Delegation&#8221; will open up the delegation menu where People Delegation is the default in the top left drop down box. The names listed above are all the previous People Delegations. To add new People Delegations, select &#8220;Add&#8221; in the green box at the top. Select the Reviewer Email whose review will be delegated to another. Next select the delegatee&#8217;s email who will be conducting the review on the reviewers behalf. In this example: Harrison&#8217;s pending access reviews will be done by Jack. Functionality: People Delegation People Delegation will affect all current and future campaigns It is NOT campaign specific Upon delegation, both parties will see the same campaign. No access is revoked from the original reviewer A &#8220;Red Exclamation&#8221; icon will appear next to a campaign that has been delegated Use Case:The owner of a review is out of office. The deadline for reviews to be completed will end before the reviewer returns to office. SecurEnds admin will delegate the OOO reviewer&#8217;s review to a trustworthy source to complete on their behalf. Initiating a Credential Delegation Navigate back to &#8220;Delegation&#8221; on the left hand side menu. Click the drop down to &#8220;Credential Delegation&#8221;. Note: Credential Delegation is application specific. Select the desired application. In the example above, Active Directory is selected: The user, Nyjah&#8217;s, email was searched for using the &#8220;Search Email&#8221;. The corresponding credential &#8220;Nhuston&#8221; appears and is selected &#8220;Tony.hawk&#8221; is selected as Reviewer Select Save to confirm delegation Delegation will now appear in list order below Functionality: Credential Delegation Credential Delegation allows an individual to review the selected user&#8217;s access every time the application is selected in a campaign Credential Delegations will overarch all other forms of delegation / workflow (example: manager in System of Record or application custodian or entitlement owner) Use Case: An administrator is responsible for reviewing the access of their application. Said administrator has been assigned the Application Custodian for this application within SecurEnds. Conducting an Application Custodian review in SecurEnds will assign all reviews to the selected custodian; however the custodian cannot review their own access. Here, the SecurEnds admin has made the credential delegation for the Application Custodian&#8217;s access to be reviewed by a separate, qualified individual.</p>
<p>The post <a href="https://www.securends.com/documentation/campaign-delegations/">Campaign Delegations</a> appeared first on <a href="https://www.securends.com">SecurEnds</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p>Campaigns can be customized further using Delegations. There are two types of delegations: <strong>People Delegations</strong> and <strong>Credential Delegations</strong>. Each delegation has a different function and resulting use case.</p>



<p>Delegation settings can be found in the &#8220;Delegation&#8221; tab under <em>Access Review</em> on the left hand menu.</p>



<h5 class="wp-block-heading" id="h-initiating-a-people-delegation">Initiating a People Delegation</h5>



<figure class="wp-block-image size-large"><img fetchpriority="high" decoding="async" width="1024" height="467" src="https://www.securends.com/wp-content/uploads/2021/05/Screen-Shot-2021-05-10-at-4.03.12-PM-1024x467.png" alt="" class="wp-image-8614" srcset="https://www.securends.com/wp-content/uploads/2021/05/Screen-Shot-2021-05-10-at-4.03.12-PM-1024x467.png 1024w, https://www.securends.com/wp-content/uploads/2021/05/Screen-Shot-2021-05-10-at-4.03.12-PM-300x137.png 300w, https://www.securends.com/wp-content/uploads/2021/05/Screen-Shot-2021-05-10-at-4.03.12-PM-768x350.png 768w, https://www.securends.com/wp-content/uploads/2021/05/Screen-Shot-2021-05-10-at-4.03.12-PM-1536x701.png 1536w, https://www.securends.com/wp-content/uploads/2021/05/Screen-Shot-2021-05-10-at-4.03.12-PM-2048x934.png 2048w" sizes="(max-width: 1024px) 100vw, 1024px" /></figure>



<p>Clicking &#8220;Delegation&#8221; will open up the delegation menu where <strong>People Delegation</strong> is the default in the top left drop down box. The names listed above are all the previous People Delegations. To add new People Delegations, select &#8220;Add&#8221; in the green box at the top.</p>



<figure class="wp-block-image size-large"><img decoding="async" width="1024" height="319" src="https://www.securends.com/wp-content/uploads/2021/05/Screen-Shot-2021-05-10-at-4.11.17-PM-1024x319.png" alt="" class="wp-image-8616" srcset="https://www.securends.com/wp-content/uploads/2021/05/Screen-Shot-2021-05-10-at-4.11.17-PM-1024x319.png 1024w, https://www.securends.com/wp-content/uploads/2021/05/Screen-Shot-2021-05-10-at-4.11.17-PM-300x93.png 300w, https://www.securends.com/wp-content/uploads/2021/05/Screen-Shot-2021-05-10-at-4.11.17-PM-768x239.png 768w, https://www.securends.com/wp-content/uploads/2021/05/Screen-Shot-2021-05-10-at-4.11.17-PM-1536x478.png 1536w, https://www.securends.com/wp-content/uploads/2021/05/Screen-Shot-2021-05-10-at-4.11.17-PM-2048x637.png 2048w" sizes="(max-width: 1024px) 100vw, 1024px" /></figure>



<p>Select the Reviewer Email whose review will be delegated to another.  Next select the delegatee&#8217;s email who will be conducting the review on the reviewers behalf. In this example: Harrison&#8217;s pending access reviews will be done by Jack.</p>



<h5 class="wp-block-heading" id="h-functionality-people-delegation">Functionality: People Delegation</h5>



<ul class="wp-block-list"><li>People Delegation will affect all current and future campaigns<ul><li>It is NOT campaign specific</li></ul></li><li>Upon delegation, both parties will see the same campaign. No access is revoked from the original reviewer<ul><li>A &#8220;<span class="has-inline-color has-vivid-red-color">Red Exclamation</span>&#8221; icon will appear next to a campaign that has been delegated</li></ul></li></ul>



<p class="has-background" style="background-color:#001b90"><span class="has-inline-color has-white-color"><strong>Use Case</strong>:</span><br><span class="has-inline-color has-white-color"><br>The owner of a review is out of office. The deadline for reviews to be completed will end before the reviewer returns to office. SecurEnds admin will delegate the OOO reviewer&#8217;s review to a trustworthy source to complete on their behalf.</span></p>



<p></p>



<h5 class="wp-block-heading" id="h-initiating-a-credential-delegation">Initiating a Credential Delegation</h5>



<p>Navigate back to &#8220;Delegation&#8221; on the left hand side menu. Click the drop down to &#8220;Credential Delegation&#8221;.</p>



<figure class="wp-block-image size-large"><img decoding="async" width="1024" height="412" src="https://www.securends.com/wp-content/uploads/2021/05/Screen-Shot-2021-05-10-at-5.04.11-PM-1024x412.png" alt="" class="wp-image-8617" srcset="https://www.securends.com/wp-content/uploads/2021/05/Screen-Shot-2021-05-10-at-5.04.11-PM-1024x412.png 1024w, https://www.securends.com/wp-content/uploads/2021/05/Screen-Shot-2021-05-10-at-5.04.11-PM-300x121.png 300w, https://www.securends.com/wp-content/uploads/2021/05/Screen-Shot-2021-05-10-at-5.04.11-PM-768x309.png 768w, https://www.securends.com/wp-content/uploads/2021/05/Screen-Shot-2021-05-10-at-5.04.11-PM-1536x618.png 1536w, https://www.securends.com/wp-content/uploads/2021/05/Screen-Shot-2021-05-10-at-5.04.11-PM-2048x824.png 2048w" sizes="(max-width: 1024px) 100vw, 1024px" /></figure>



<p><strong>Note</strong>: Credential Delegation is application specific. Select the desired application.</p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="286" src="https://www.securends.com/wp-content/uploads/2021/05/Screen-Shot-2021-05-10-at-5.14.08-PM-1024x286.png" alt="" class="wp-image-8619" srcset="https://www.securends.com/wp-content/uploads/2021/05/Screen-Shot-2021-05-10-at-5.14.08-PM-1024x286.png 1024w, https://www.securends.com/wp-content/uploads/2021/05/Screen-Shot-2021-05-10-at-5.14.08-PM-300x84.png 300w, https://www.securends.com/wp-content/uploads/2021/05/Screen-Shot-2021-05-10-at-5.14.08-PM-768x215.png 768w, https://www.securends.com/wp-content/uploads/2021/05/Screen-Shot-2021-05-10-at-5.14.08-PM-1536x429.png 1536w, https://www.securends.com/wp-content/uploads/2021/05/Screen-Shot-2021-05-10-at-5.14.08-PM-2048x572.png 2048w" sizes="(max-width: 1024px) 100vw, 1024px" /></figure>



<p>In the example above, Active Directory is selected:</p>



<ul class="wp-block-list"><li>The user, Nyjah&#8217;s, email was searched for using the &#8220;Search Email&#8221;.</li><li>The corresponding credential &#8220;Nhuston&#8221; appears and is selected </li><li>&#8220;Tony.hawk&#8221; is selected as Reviewer</li><li>Select Save to confirm delegation<ul><li>Delegation will now appear in list order below</li></ul></li></ul>



<h5 class="wp-block-heading" id="h-functionality-credential-delegation">Functionality: Credential Delegation</h5>



<ul class="wp-block-list"><li>Credential Delegation <strong>allows an individual to review the selected user&#8217;s access every time the application is selected in a campaign</strong></li><li>Credential Delegations will overarch all other forms of delegation / workflow (example: manager in System of Record or application custodian or entitlement owner)</li></ul>



<p class="has-background" style="background-color:#001b90"><span class="has-inline-color has-white-color"><strong>Use Case</strong>:<br><br>An administrator is responsible for reviewing the access of their application. Said administrator has been assigned the Application Custodian for this application within SecurEnds. </span><br><br><span class="has-inline-color has-white-color">Conducting an Application Custodian review in SecurEnds will assign all reviews to the selected custodian; however the custodian cannot review their own access. Here, the SecurEnds admin has made the credential delegation for the Application Custodian&#8217;s access to be reviewed by a separate, qualified individual. </span></p>
<p>The post <a href="https://www.securends.com/documentation/campaign-delegations/">Campaign Delegations</a> appeared first on <a href="https://www.securends.com">SecurEnds</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.securends.com/documentation/campaign-delegations/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>How do I manage unmatched records for my application that I cannot match (i.e Vendor records, old credentials no longer in the SOR, etc.)?</title>
		<link>https://www.securends.com/documentation/manage-service-accounts-with-pseudo-user/</link>
					<comments>https://www.securends.com/documentation/manage-service-accounts-with-pseudo-user/#respond</comments>
		
		<dc:creator><![CDATA[secure]]></dc:creator>
		<pubDate>Wed, 10 Mar 2021 20:58:30 +0000</pubDate>
				<guid isPermaLink="false">https://www.securends.com/?post_type=docs&#038;p=7419</guid>

					<description><![CDATA[<p>There is a requirement to match identities between the System of Record (SOR) and an application being connected to the SecurEnds tool in order for the credential to be included in reviews. Applications match to the system of record using three different methods: 1) a first/last name, 2) an email address or 3) perhaps an Employee ID between SOR and application. In all three cases, that attribute needs to already be present in the SOR in order to match against. As an example, a credential in your application which represents a Vendor with an email address may not be present in your HR system of record. There is an alternate solution or strategy that can be leveraged. The Psuedo-Account Strategy You can consider this strategy for those Active/Terminated users and for records that cannot be matched to an identity in the People data (populated by your SOR sync). Simply using the Assign feature for the unmatched users and assigning them to a user in the People view may &#8220;muddy&#8221; the list of entitlements under that user you assigned the unmatched record to. Now that manager needs to review a credential, he has no idea about for one of his direct reports. Meaning, when you view that user&#8217;s list of entitlements, they will have their own entitlements for the respective application PLUS the credential and entitlements of this unmatched user. Not really a true view of that person&#8217;s entitlement list. Instead, we can create a new, fake identity or Pseudo-user within the People data. By providing a meaningful, &#8220;smart&#8221; name to represent the unmatched user, coupled with a unique, fake &#8220;smart&#8221; email address; you can then assign this pseudo user to an actual manager email address whom you would like to review these accounts/entitlements. A Bulk Assign of one or more unmatched records to this pseudo-user will cause those unmatched users to become matched. Then that pseudo-user will appear in reviews under that manager user access review list. Here is an example of creating a pseudo user. Keep in mind that you cannot edit this user once you select Create without using an import of a CSV approach. People -&#62; Select Add Employee Type = Regular Employee First Name = AppName Employee Last Name = Vendor Account Employee Email Address = noemail1@mycompany.com Manager Email ID = The email address of the manager who will be reviewing the vendor account(s) entitlement or users. You can add additional attributes if needed but that is optional Then, when you go thru the Bulk Assign, update the IAM User field within the CSV to noemail1@mycompany.com. Then upload. All those records will be assigned to &#8220;Mr. Appname Vendor Account&#8221; who has the manager you provided. You can create as many pseudo-users as you need to account until all the unmatched records that you want to assign is completed. Keep in mind that each pseudo-user will need their own dummy email address. How do I match Service Accounts? How do I review role or group permissions for CSV applications?</p>
<p>The post <a href="https://www.securends.com/documentation/manage-service-accounts-with-pseudo-user/">How do I manage unmatched records for my application that I cannot match (i.e Vendor records, old credentials no longer in the SOR, etc.)?</a> appeared first on <a href="https://www.securends.com">SecurEnds</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<h2 class="wp-block-heading" id="h-"></h2>



<p>There is a requirement to match identities between the System of Record (SOR) and an application being connected to the SecurEnds tool in order for the credential to be included in reviews.  Applications match to the system of record using three different methods: 1) a first/last name, 2) an email address or 3) perhaps an Employee ID between SOR and application.  In all three cases, that attribute needs to already be present in the SOR in order to match against.  As an example, a credential in your application which represents a Vendor with an email address may not be present in your HR system of record.  There is an alternate solution or strategy that can be leveraged.  </p>



<p><strong>The Psuedo-Account Strategy</strong></p>



<p>You can consider this strategy for those Active/Terminated users and for records that cannot be matched to an identity in the People data (populated by your SOR sync).</p>



<p>Simply using the Assign feature for the unmatched users and assigning them to a user in the People view may &#8220;muddy&#8221; the list of entitlements under that user you assigned the unmatched record to.  Now that manager needs to review a credential, he has no idea about for one of his direct reports. Meaning, when you view that user&#8217;s list of entitlements, they will have their own entitlements for the respective application <strong>PLUS </strong>the credential and entitlements of this unmatched user. Not really a true view of that person&#8217;s entitlement list.</p>



<p>Instead, we can create a new, fake identity or Pseudo-user within the People data.  By providing a meaningful, &#8220;smart&#8221; name to represent the unmatched user, coupled with a unique, fake &#8220;smart&#8221; email address; you can then assign this pseudo user to an actual manager email address whom you would like to review these accounts/entitlements. A <a href="https://www.securends.com/documentation/unmatched-credentials-in-applications/"><span style="text-decoration: underline;"><strong><span class="has-inline-color has-vivid-cyan-blue-color">Bulk Assign</span></strong></span></a> of one or more unmatched records to this pseudo-user will cause those unmatched users to become matched. Then that pseudo-user will appear in reviews under that manager user access review list. Here is an example of creating a pseudo user.  <strong>Keep in mind that you cannot edit this user once you select Create without using an import of a CSV approach.</strong></p>



<ul class="wp-block-list"><li>People -&gt; Select Add</li><li>Employee Type = Regular</li><li>Employee First Name = AppName</li><li>Employee Last Name = Vendor Account</li><li>Employee Email Address = noemail1@mycompany.com</li><li>Manager Email ID = The email address of the manager who will be reviewing the vendor account(s) entitlement or users.</li><li>You can add additional attributes if needed but that is optional</li></ul>



<p>Then, when you go thru the Bulk Assign, update the <strong>IAM User</strong> field within the CSV to noemail1@mycompany.com. Then upload. All those records will be assigned to &#8220;Mr. Appname Vendor Account&#8221; who has the manager you provided.  You can create as many pseudo-users as you need to account until all the unmatched records that you want to assign is completed. <strong>Keep in mind that each pseudo-user will need their own dummy email address</strong>.</p>



<p class="has-vivid-red-color has-text-color"><a href="https://www.securends.com/documentation/service-accounts/"><span class="has-inline-color has-vivid-red-color" style="text-decoration: underline;">How do I match Service Accounts?</span></a></p>



<p><a href="https://www.securends.com/documentation/group-reviews/" target="_blank" rel="noreferrer noopener"><span class="has-inline-color has-vivid-red-color"><span style="text-decoration: underline;">How do I review role or group permissions for CSV applications?</span></span></a></p>
<p>The post <a href="https://www.securends.com/documentation/manage-service-accounts-with-pseudo-user/">How do I manage unmatched records for my application that I cannot match (i.e Vendor records, old credentials no longer in the SOR, etc.)?</a> appeared first on <a href="https://www.securends.com">SecurEnds</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.securends.com/documentation/manage-service-accounts-with-pseudo-user/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Sensitive Rights / Privileged Access Reviews</title>
		<link>https://www.securends.com/documentation/sensitive-rights-privileged-access-reviews/</link>
					<comments>https://www.securends.com/documentation/sensitive-rights-privileged-access-reviews/#respond</comments>
		
		<dc:creator><![CDATA[secure]]></dc:creator>
		<pubDate>Wed, 10 Mar 2021 21:00:20 +0000</pubDate>
				<guid isPermaLink="false">https://www.securends.com/?post_type=docs&#038;p=7421</guid>

					<description><![CDATA[<p>Campaign creation: &#8220;Include all Entitlements&#8221;, select &#8220;No&#8221; -> Choose desired entitlements to include in campaign</p>
<p>The post <a href="https://www.securends.com/documentation/sensitive-rights-privileged-access-reviews/">Sensitive Rights / Privileged Access Reviews</a> appeared first on <a href="https://www.securends.com">SecurEnds</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p>Campaign creation: &#8220;Include all Entitlements&#8221;, select &#8220;No&#8221; -> Choose desired entitlements to include in campaign</p>
<p>The post <a href="https://www.securends.com/documentation/sensitive-rights-privileged-access-reviews/">Sensitive Rights / Privileged Access Reviews</a> appeared first on <a href="https://www.securends.com">SecurEnds</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.securends.com/documentation/sensitive-rights-privileged-access-reviews/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Campaign Error Handling</title>
		<link>https://www.securends.com/documentation/campaign-error-handling/</link>
					<comments>https://www.securends.com/documentation/campaign-error-handling/#respond</comments>
		
		<dc:creator><![CDATA[secure]]></dc:creator>
		<pubDate>Wed, 10 Mar 2021 21:01:09 +0000</pubDate>
				<guid isPermaLink="false">https://www.securends.com/?post_type=docs&#038;p=7423</guid>

					<description><![CDATA[<p>Action Button &#8220;View&#8221; Campaign Pre-Launch&#8230;.view users / match count / reviewers before Launching</p>
<p>The post <a href="https://www.securends.com/documentation/campaign-error-handling/">Campaign Error Handling</a> appeared first on <a href="https://www.securends.com">SecurEnds</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p>Action Button &#8220;View&#8221; Campaign Pre-Launch&#8230;.view users / match count / reviewers before Launching</p>
<p>The post <a href="https://www.securends.com/documentation/campaign-error-handling/">Campaign Error Handling</a> appeared first on <a href="https://www.securends.com">SecurEnds</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.securends.com/documentation/campaign-error-handling/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
	</channel>
</rss>
