• Votes

    2

    The REMOVE_PERMISSION_ASSIGNMENT change items in the change set should ...

    In version 2.5.1, each change item in the REMOVE_PERMISSION_ASSIGNMENT change set contains the permission name, but does not contain the permission ID from source. The ...

  • Votes

    1

    Software appliance installation option

    Have a software appliance option to install IG. That would make easier the deployment of it in projects, POCs, demos, and mainly for maintenance of the patches/updates in ...

  • Votes

    2

    Have a SAP collector that gets object authorization and transactions ...

    Collect object authorization and transactions that users are assigned on SAP system. That makes possible to have SoD at that level of access in SAP systems. This is a ...

  • Votes

    8

    Have a native linux and windows local account collector

    Have a native linux and windows collector to get local accounts to identify and review orphans accounts on these systems. This is a very common and important requirement.

  • Votes

    5

    SoD Policies need a periodic review process to satisfy audit ...

    From the customer: A required expiration/approval cycle for SOD policies: On a periodic basis (configurable), SoD policies will move to a “Review & Approval Required” ...

  • Planned

    3

    Review definition can initiate a query onto the IG application ...

    Review definition can initiate a SQL select onto the IG application database to obtain a Review Set For a User or Account Review - the Review Set may be obtained live at ...

  • Planned

    3

    Metadata collection for Application Owners, Reviewers, Monitors

    Customer maintains names and userids of (both Business & Technical) Application Owners, Reviewers, and Monitors per Identity Governance application and/or review within ...

  • Votes

    4

    Add capability to generate & display email messages within the IG ...

    Capability to generate & display email messages within the application. In a non-Production environment, it is essential to generate the various IG email messages, but ...

  • Planned

    7

    Provide a Coverage File option in the Unmapped Accounts Review ...

    Provide a Coverage File option in the Unmapped Accounts Review definition Allow account or permission data to assign the (unmapped account) review item to a certain ...

  • Votes

    2

    Add connection failoverPartner configuration to JDBC collector

    Customer provided this JDBC connection string for an Application collector. jdbc:sqlserver://LENVSSDS10;databaseName=GetAccess;failoverPartner=COLVSSDS10 At any given ...

  • Votes

    4

    Add query capability to the CSV collector

    Add query capability to the CSV collector In an Application collector with a CSV source file, adding a query statement capability (SQL SELECT) against the CSV data would ...

  • Planned

    11

    Data Purge Utility needs to become an automatic process

    The Data Purge Utility needs to become an automatic process. Increasingly, Application Administrators are not permitted server access. Provide Purge Utility parameter ...

  • Votes

    7

    Request for time limited access and for access in the future

    When requesting access it is sometime needed to be able to limit the request to a specific time period already at access time. It is similar to the possibility in ...

  • Planned

    4

    IG: Compare the IdM expected status with the actual status in the ...

    IG customers with an IdM solution (independent of vendor) do heavily rely on the status of users and permissions in their IdM system. The status of the IdM system is ...

  • Votes

    5

    Separation of IG application from web front-end

    Today the web-frontend TOMCAT and the Identity Governance application has to be placed on the same server. Many customers see this as a security risk, since the IG ...

  • Planned

    5

    Manager employee relationship review

    Before reviewing employees access rights many companies would like to have a review of the manager/employee relationship. Make it possible to have Identity review, ...

  • Votes

    6

    Need for grouping AD permissions into application specific groups

    AD is used as the authorization and authentication source for many applications via federation. A typical setup is that a number of security groups are created in AD to ...

  • Planned

    5

    Same information about Identities etc. by approving an access request ...

    When approving an access request the information about e.g. identities is somewhat limited in comparison to the same information one can get at reviews. Give the same ...

  • Votes

    2

    Add fulfilment connector to Active directory and FIM/MIM.

    This would enable the enhancement of MS centric environments with more complete Identity governance and also allow better request/approve functionality. Additionally a ...

  • Votes

    8

    Handling "Orphan Reviews"

    If a reviewer is no longer valid while a review is in flight, the system should escalate the "orphaned review" to the original reviewer's supervisor and up the chain.