How to trigger Access Analyzer - Comparing user records through script background
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
3 weeks ago
I would like to know the class and code details how to trigger Access Analyzer - simulators from backend scripts. I have tried below script include but couldn't figure it out...!!!
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
3 weeks ago
Hi,
The script includes mentioned, and the underlaying API can't be accessed outside of the Access Analyser scope.
The kye JS API is "sn_identity.IdentitySecurityApi". This has been security restricted and can't be invoked from the global scope, or a customer scope
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
3 weeks ago
I got to know that sn_identity.IdentitySecurityApi is the main API behind, how about can we trigger below endpoint to get the results?
https://<instance_id>.service-now.com/now/access-analyzer/user-profile-comparison/<source_user_sys_i...
looking for a workaround where I can use this functionality and automate the roles assignment process.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
3 weeks ago
Yes that I got to know the main backend ServiceNow API is "sn_identity.IdentitySecurityApi" and there are security restrictions to call this directly.
I am looking for a workaround or any API through we can get the same results. This I am trying to automate the role assignment process completely. Can we use below endpoint to get the Groups, Roles response?
https://<instance_id>.service-now.com/now/access-analyzer/user-profile-comparison/<source_user_sys_i...>/<target_user_sys_id>
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
3 weeks ago
┌──────────────────────────────────────┐
│ ACCESS ANALYZER │
│ Compare User Records │
└──────────────────┬───────────────────┘
│
▼
┌──────────────────────────────────────┐
│ UX ROUTE │
│ user-profile-comparison │
└──────────────────┬───────────────────┘
│
▼
┌──────────────────────────────────────┐
│ sys_ux_macroponent │
│ User Profile Comparison Default │
│ b2d8fb3e77403110638cfe21fe5a99fa │
└──────────────────┬───────────────────┘
│
▼
┌──────────────────────────────────────┐
│ sys_ux_client_script │
│ Profile Comparison Data Handler │
│ d122fd4577503110638cfe21fe5a99e8 │
└──────────────────┬───────────────────┘
│
▼
┌──────────────────────────────────────┐
│ sys_ux_data_broker_graphql │
│ 21f155c65310101024e5ddeeff7b1210 │
└──────────────────┬───────────────────┘
│
▼
┌──────────────────────────────────────┐
│ DATA │
│ │
│ sys_user │
│ sys_user_has_role │
│ sys_user_grmember │
└──────────────────┬───────────────────┘
│
│ tableData
▼
┌──────────────────────────────────────┐
│ sys_ux_client_script_include │
│ sn_access_analyzer.AccessComparator │
│ 9598876f432131102c5119405bb8f2d7 │
└──────────────────┬───────────────────┘
│
▼
┌──────────────────────────────────────┐
│ COMPARATORS │
│ │
│ UserComparator │
│ RoleComparator │
│ GroupComparator │
└──────────────────┬───────────────────┘
│
▼
┌──────────────────────────────────────┐
│ getComparisonResult() │
└──────────────────┬───────────────────┘
│
▼
┌──────────────────────────────────────┐
│ OOB COMPARE USER RECORDS RESULT │
│ │
│ User → attributes │
│ Roles → 38 differences │
│ Groups → 3 differences │
└──────────────────────────────────────┘
