- 21 Jun 2024
- 4 Minutes to read
- Print
- DarkLight
- PDF
How to Review Birthright Access
- Updated on 21 Jun 2024
- 4 Minutes to read
- Print
- DarkLight
- PDF
This guide walks you through how to review birthright access for one or more roles in your organization.
Reviewing birthright access is a crucial component of any Identity governance program. Running quarterly birthright access reviews helps identify access drift, clean up over-provisioned roles, and reduce the scope of User Access Reviews.
Before you begin:
Identity Attribute mapping has been configured
Established a Role Based Access Control structure
Roles are populated with Identities and entitlements
Assigned an owner for in scope roles
Create a Birthright Access Review
Set Up the Birthright Access Review
Navigate to the New Access Review page (Access Reviews > Create New or https://your_tenant.claritysecurity.io/review/create)
Click Create Role Access Review
Fill in the information in the left column:
Review Name - Birthright Review - Demo
Assign Items to - Role Owners
Default Reviewer If No Supervisor/Owner Found - Clarity Admin -- admin@claritysecurity or yourself
Frequency - Once
Start Review On - Today's Date
Business Days to Complete Review - 15
Scope the Review
In the Type drop-down select Specific Roles.
In the Role drop-down type and select Admin, or any other role that has birthright access which can be found in the Role side navigation.
Optional settings:
Use Entitlement Friendly Name will display the friendly name of an entitlement, which is configured in the Entitlement Bulk Editor. If you do not have friendly names configured, the default name will be used.
Delay Email Notifications allows you to control when reviewers are notified about their assigned items.
Exclusions are how to filter out data such as applications or entitlements from the scope of the review.
Generate the Review
Review that all of the following fields have a value set:
Review Name - Birthright Review - Demo
Assign Items Reviews to - Role Owners
Default Reviewer If No Supervisor/Owner Found - Clarity Admin
Frequency - Once
Start Review On - Today’s Date
Business Days to Complete Review - 15
Type - Specific Roles
Roles - Admin/Admin
Click Create Review
Clean up
After generating the review, look through the data, and explore the review and remediation capabilities.
Once finished, navigate to the access review home screen https://your_tenant.claritysecurity.io/review
Locate the review we just created --> Birthright Review - Demo
Click the ACTIONS drop-down.
Click Delete
If you click the button Archived Templates there will be a template with the name Role Review - Demo. You can use this template to generate future Birthright Access Reviews
Common Support Questions
Can I select multiple roles in a single Birthright Access Review?
Yes! After you click on the first role, type in the name and select the applicable role.
Why did my review not appear in the In Progress reviews?
Potential Cause: If the roles you selected do not have any birth right access, there will be no data to review.
Confirmation Step click on the Ready to Finalize tab. If the review is there, follow the above Clean Up steps.
Why do I see duplicate roles in the Roles drop-down?
Potential Cause: One or more users has a Role attribute that contains leading or trailing whitespace. If this happens, there will be 2 roles with nearly identical names.
Confirmation Steps go to the Role side navigation and search for the role name. Copy the two similar names into a text editor and compare. If they are truly identical, reach out to support@claritysecurity.com
Why don't I see someone in the Default Reviewer-drop down?
Potential Cause The desired default reviewer does not have the Clarity Entitlement Access Certification Admin. Grant them this entitlement and go back to step 1 - Set Up the Birthright Access Review.
Need help?
If you have any problems, contact your customer success team. You can also get in touch with our general support via email, open a support ticket. Our general support team is available Monday - Friday from 8:00 AM - 6:30 PM CST.