Create a machine identity access control
Enable administrators to define and enforce granular control for integration users by introducing User Access Profiles. This feature provides an additional layer of security and control, allowing admins to specify the exact resources (REST APIs and SOAP APIs) that an integration user can access, ensuring tighter governance and minimizing security risks.
Before you begin
Role required: admin
Procedure
Navigate to All > System Security > Machine Identity Access Controls.
Select the New button.
Fill in the fields of the form.
| Field | Description | ||
|---|---|---|---|
| Name | Name of the access control record. | ||
| Application | Application containing the record. | ||
| Description | Description of the record. | ||
| Active | Determines if the policy is active | ||
| REST API Policy | Select the target REST API policy. Note: Select the Image omitted: machine-acl-lock-icon.png SOAP API PolicyLock and the [Omitted image "machine-acl-search-icon.png"] Alt text: Search icon to add a policy.</td></tr><tr><td> | Select the target SOAP API policy. Note: Select the Image omitted: machine-acl-lock-icon.png TablesLock and the [Omitted image "machine-acl-search-icon.png"] Alt text: Search icon to add a policy.</td></tr><tr><td> | Select the tables this policy applies to |
| Applies to Child Table | Check this to apply the policy to child tables of the Tables field |
Select the
Insert a row belowprompt and add users to apply the control to.You can add multiple users to the access control.
Note: You can only select users with Web Service Access.
Select Submit.
Result
The following is an example of a machine identity access control form that has been filled out:
An example of a machine identity access control form filled out.
A user with an machine identity access control cannot access any other APIs (REST or SOAP) and will only be able to access the resources explicitly stated in the access control, even if they have the required roles.