<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>question Re: Vendor Portal Security in GRC forum</title>
    <link>https://www.servicenow.com/community/grc-forum/vendor-portal-security/m-p/2817252#M16262</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://www.servicenow.com/community/user/viewprofilepage/user-id/91822"&gt;@danielyanof&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Yes, you can enforce MFA for vendor logins. You can use the adaptive authentication - MFA context policy to enforce this security control.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.servicenow.com/bundle/washingtondc-platform-security/page/integrate/authentication/concept/mfa-auth-context.html" target="_self"&gt;Here&lt;/A&gt; is the product documentation.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You can create a role filter criteria with the role(s) provided to vendor portal users.&lt;/P&gt;
&lt;P&gt;Then, you can create an adaptive authentication policy and use this criterion. You can add a condition and associate the policy with the MFA context record.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For additional details, please refer to this 30-minute &lt;A href="https://nowlearning.servicenow.com/lxp/en/now-platform/adaptive-authentication-overview?id=learning_course_prev&amp;amp;course_id=8d02d74b936e3d14fb94b4886cba103f" target="_self"&gt;Adaptive Authentication course on NowLearning.&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;Randheer&lt;/P&gt;</description>
    <pubDate>Tue, 06 Feb 2024 15:11:27 GMT</pubDate>
    <dc:creator>Randheer Singh</dc:creator>
    <dc:date>2024-02-06T15:11:27Z</dc:date>
    <item>
      <title>Vendor Portal Security</title>
      <link>https://www.servicenow.com/community/grc-forum/vendor-portal-security/m-p/2815951#M16254</link>
      <description>&lt;P class=""&gt;Hello,&lt;/P&gt;&lt;P class=""&gt;&amp;nbsp;&lt;/P&gt;&lt;P class=""&gt;Has anyone setup additional types of authentication for the TPRM (Third-party risk management) vendor portal (/svdp)?&lt;/P&gt;&lt;P class=""&gt;&amp;nbsp;&lt;/P&gt;&lt;P class=""&gt;OOTB uses local accounts using the Vendor Contact records, and there's restrictions for these 3rd party vendor contacts to only access the vendor portal.&lt;/P&gt;&lt;P class=""&gt;&amp;nbsp;&lt;/P&gt;&lt;P class=""&gt;For example, any experience setting up MFA or other types of authentication, and if so, any tips on configuring that?&lt;/P&gt;&lt;P class=""&gt;&amp;nbsp;&lt;/P&gt;&lt;P class=""&gt;Thank you, Dan&lt;/P&gt;</description>
      <pubDate>Mon, 05 Feb 2024 19:37:22 GMT</pubDate>
      <guid>https://www.servicenow.com/community/grc-forum/vendor-portal-security/m-p/2815951#M16254</guid>
      <dc:creator>danielyanof</dc:creator>
      <dc:date>2024-02-05T19:37:22Z</dc:date>
    </item>
    <item>
      <title>Re: Vendor Portal Security</title>
      <link>https://www.servicenow.com/community/grc-forum/vendor-portal-security/m-p/2817108#M16261</link>
      <description>&lt;P&gt;I have the same question: Can we set up MFA for vendor portal users? or any authentication?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 06 Feb 2024 14:01:15 GMT</pubDate>
      <guid>https://www.servicenow.com/community/grc-forum/vendor-portal-security/m-p/2817108#M16261</guid>
      <dc:creator>Sameer32</dc:creator>
      <dc:date>2024-02-06T14:01:15Z</dc:date>
    </item>
    <item>
      <title>Re: Vendor Portal Security</title>
      <link>https://www.servicenow.com/community/grc-forum/vendor-portal-security/m-p/2817252#M16262</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://www.servicenow.com/community/user/viewprofilepage/user-id/91822"&gt;@danielyanof&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Yes, you can enforce MFA for vendor logins. You can use the adaptive authentication - MFA context policy to enforce this security control.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.servicenow.com/bundle/washingtondc-platform-security/page/integrate/authentication/concept/mfa-auth-context.html" target="_self"&gt;Here&lt;/A&gt; is the product documentation.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You can create a role filter criteria with the role(s) provided to vendor portal users.&lt;/P&gt;
&lt;P&gt;Then, you can create an adaptive authentication policy and use this criterion. You can add a condition and associate the policy with the MFA context record.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For additional details, please refer to this 30-minute &lt;A href="https://nowlearning.servicenow.com/lxp/en/now-platform/adaptive-authentication-overview?id=learning_course_prev&amp;amp;course_id=8d02d74b936e3d14fb94b4886cba103f" target="_self"&gt;Adaptive Authentication course on NowLearning.&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;Randheer&lt;/P&gt;</description>
      <pubDate>Tue, 06 Feb 2024 15:11:27 GMT</pubDate>
      <guid>https://www.servicenow.com/community/grc-forum/vendor-portal-security/m-p/2817252#M16262</guid>
      <dc:creator>Randheer Singh</dc:creator>
      <dc:date>2024-02-06T15:11:27Z</dc:date>
    </item>
    <item>
      <title>Re: Vendor Portal Security</title>
      <link>https://www.servicenow.com/community/grc-forum/vendor-portal-security/m-p/2898360#M16888</link>
      <description>&lt;P&gt;hello&amp;nbsp;&lt;a href="https://www.servicenow.com/community/user/viewprofilepage/user-id/159489"&gt;@Randheer Singh&lt;/a&gt;&amp;nbsp;and team,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We've reviewed the product documentation and not sure how we can handle our situation.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The customer requires IP access controls such that only users who are in authorized network locations (based upon IP address) can access the ServiceNow instance.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The third party users will not be included in those IP access controls, e.g., they are not in an authorized network location, and they will have the external role.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It seems like the IP Filter policy can be setup in the pre authorization context for adaptive authentication to allow authorized users but not sure how that would work for the third party users that do not match the IP filter.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is there a way to use the IP Filter and MFA role based context to satisfy this use case for the third party portal users?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you, Dan&lt;/P&gt;</description>
      <pubDate>Mon, 15 Apr 2024 21:05:40 GMT</pubDate>
      <guid>https://www.servicenow.com/community/grc-forum/vendor-portal-security/m-p/2898360#M16888</guid>
      <dc:creator>danielyanof</dc:creator>
      <dc:date>2024-04-15T21:05:40Z</dc:date>
    </item>
    <item>
      <title>Re: Vendor Portal Security</title>
      <link>https://www.servicenow.com/community/grc-forum/vendor-portal-security/m-p/2902191#M16929</link>
      <description>&lt;P&gt;Anyone have an answer for the above?&lt;/P&gt;</description>
      <pubDate>Thu, 18 Apr 2024 13:06:08 GMT</pubDate>
      <guid>https://www.servicenow.com/community/grc-forum/vendor-portal-security/m-p/2902191#M16929</guid>
      <dc:creator>robspence</dc:creator>
      <dc:date>2024-04-18T13:06:08Z</dc:date>
    </item>
    <item>
      <title>Re: Vendor Portal Security</title>
      <link>https://www.servicenow.com/community/grc-forum/vendor-portal-security/m-p/2903151#M16939</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://www.servicenow.com/community/user/viewprofilepage/user-id/91822"&gt;@danielyanof&lt;/a&gt;&amp;nbsp;&lt;a href="https://www.servicenow.com/community/user/viewprofilepage/user-id/465661"&gt;@robspence&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;You have to use the post-authentication context policy to apply this security. In the pre-authentication context policy, you can not use role/group based conditions.&lt;BR /&gt;&lt;BR /&gt;In addition to that you should also consider using API access policy to apply IP protection for your non-interactive access.&lt;BR /&gt;&lt;BR /&gt;Thanks,&lt;/P&gt;
&lt;P&gt;Randheer&lt;/P&gt;</description>
      <pubDate>Fri, 19 Apr 2024 08:33:36 GMT</pubDate>
      <guid>https://www.servicenow.com/community/grc-forum/vendor-portal-security/m-p/2903151#M16939</guid>
      <dc:creator>Randheer Singh</dc:creator>
      <dc:date>2024-04-19T08:33:36Z</dc:date>
    </item>
    <item>
      <title>Re: Vendor Portal Security</title>
      <link>https://www.servicenow.com/community/grc-forum/vendor-portal-security/m-p/2903484#M16941</link>
      <description>&lt;P&gt;Thank you,&amp;nbsp;&lt;a href="https://www.servicenow.com/community/user/viewprofilepage/user-id/159489"&gt;@Randheer Singh&lt;/a&gt;,&amp;nbsp;for your reply.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The issue we have is that the 3rd party contacts will not pass the IP filter in order to attempt a login, and therefore I assume it will not reach the post-authentication context policy.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I assume this is not the first time for this scenario for the TPRM third party portal.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any advice or suggestions? Or can you check with others?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks again, Dan&lt;/P&gt;</description>
      <pubDate>Fri, 19 Apr 2024 12:30:38 GMT</pubDate>
      <guid>https://www.servicenow.com/community/grc-forum/vendor-portal-security/m-p/2903484#M16941</guid>
      <dc:creator>danielyanof</dc:creator>
      <dc:date>2024-04-19T12:30:38Z</dc:date>
    </item>
    <item>
      <title>Re: Vendor Portal Security</title>
      <link>https://www.servicenow.com/community/grc-forum/vendor-portal-security/m-p/2903745#M16943</link>
      <description>&lt;P&gt;Hi &lt;a href="https://www.servicenow.com/community/user/viewprofilepage/user-id/91822"&gt;@danielyanof&lt;/a&gt;&amp;nbsp;.&lt;BR /&gt;I'm sorry, I was not explicit in saying you can NOT use the pre-auth context policy.&lt;BR /&gt;&lt;BR /&gt;For your use case, you have to use the post-authentication context policy along with other protections like API access policies and session validation context policy (Available from the W release)&lt;BR /&gt;&lt;BR /&gt;Thanks,&lt;/P&gt;
&lt;P&gt;Randheer&lt;/P&gt;</description>
      <pubDate>Fri, 19 Apr 2024 15:13:27 GMT</pubDate>
      <guid>https://www.servicenow.com/community/grc-forum/vendor-portal-security/m-p/2903745#M16943</guid>
      <dc:creator>Randheer Singh</dc:creator>
      <dc:date>2024-04-19T15:13:27Z</dc:date>
    </item>
    <item>
      <title>Re: Vendor Portal Security</title>
      <link>https://www.servicenow.com/community/grc-forum/vendor-portal-security/m-p/2908732#M16994</link>
      <description>&lt;P&gt;Thank you for the clarifications. I heard some good feedback from our dev team that it's working. Next step is to review with the customer and try in some other environments.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 24 Apr 2024 16:16:02 GMT</pubDate>
      <guid>https://www.servicenow.com/community/grc-forum/vendor-portal-security/m-p/2908732#M16994</guid>
      <dc:creator>danielyanof</dc:creator>
      <dc:date>2024-04-24T16:16:02Z</dc:date>
    </item>
  </channel>
</rss>

