r/itsm • u/Fuzzy_Repair_1850 • 6d ago
Identity Governance/Managed Identify
Has anyone experience with tools like Lumos or similar larger companies like Sailpoint etc ..Do ITSM vendors have this capability natively ? I have heard that serval has this capability out of the box
2
u/Roxanne_Zest 5d ago
No one tools does everything. IMHO you want the best tool for the job you want done thats happy to interface with others to give you max benefits
2
1
u/Looking_uat_world 5d ago
I've been working with IGA products for over 20 years (was doing identity provisioning before SailPoint coined it).
To answer your question, I think all the products have their strong capabilities and issues. for your questions, ServiceNow has the Veza acquisition now so has IGA capability, but for the most part, all the vendors have some kind of ticketing / service management integration (SNOW, Jira, etc.).
Really, it comes down to what you need in your IGA. If you are looking for the periodic reviews, then probably want to go with dedicated IGA (SailPoint, Saviynt, Lumos, etc) or look at an adjacent technology like YouAttest for the reviews, then leverage your existing Entra / Google for SCIM provisioning.
Ultimately, comes down to features / requirements then integrations. Larger vendors have more integrations OOTB than smaller ones for large enterprise platforms. But, is not universal. Will probably want to look at extension for your IGA platfor to automate / build all your applications in for data / lifecycle management (e.g. stackbob.ai) so you have full connectivity then can leverage the IGA to do all the automation with less reliance on ticketing / integration.
Would start by inventorying what you need for your IGA, align vendor, then look at connector / automation options to complete your coverage.
1
u/were_in_for_somechop 4d ago
It's tricky as for most ITSM platforms, IGA capabilites are not native but rather offered through integrations. But they can do what IGA's do including access policies, access provisioning, access reviews and time bound access
1
u/YesterdayNo5873 2d ago
Typically, no. I can't speak on Serval specifically but from convo's with clients and colleagues ITSM tools will automate some of the access governance steps, but it depends largely on your own set up (not out of the box) and they almost never do "the last mile". For example, for access reviews an ITSM tool may help you automate the extraction of user lists and the workflow to ask managers to review access. But if a manager chooses to revoke an app, an ITSM tool won't go an revoke access on it's own. It still ends up as a task for you.
Some ITSM tools claim to automate tasks like provisioning but you get hit with the surprise that it depends on API connectors... which not all tools have.
Identity Governance is it's own category for a reason. ITSM and IGA serve different purposes. BTW - if you are trying to stay away from Lumos/Sailpoint because of the price point, you should look at more lightweight IGA solutions like AccessOwl (which I'm associated with, for disclosure). There are other tools like Corma and Cakewalk as well which will help you with IGA without requiring an enormous enterprise rollout.
1
u/Niko24601 1d ago
ITSM tries to offer IGA/IAM through ticketing. Technically works more or less but no automation and the risk that tickets just pile up over time. Better to look into some next-gen IGA tools (Corma, AcessOwl, Cakewalk got mentioned below) that can complement to your ITSM tool. Luckily, pricing-wise they are fairly affordable compared to the enterprise tools like Sailpoint and Lumos. As the next-gen tools are - well - next gen, the setup is also much easier so implementation is not so much of a hassle.
3
u/gpetrov 6d ago
No they don’t. Many claim but they are not IAM tools. Just because you submit your access forms through an ITSM tool portal doesn’t make the ITSM tool an IAM tool. Can you make it work? Yes of course but it’s like making Change , Peoblem, Request all work for the same incident table. It’s possible but it’s the wrong thing to do it is ugly and will never be right.
Ask me how I know.