Skip to content

Conversation

@dhs-BI
Copy link

@dhs-BI dhs-BI commented Feb 3, 2025

Rotated the IPSIE Level tables, aligned the longer descriptions with the new tables.

Open questions:

IL2 - should JIT be allowed? This is in conflict with pre-provisioning/deprovisioning.

E1 - This is weak guidance, I think it should be removed OR the MAY changed to a MUST for both apps and identity services.

First draft, entitlements is not complete.
Completed rotation of the tables and aligning the descriptions to the new table structure.
@dhs-BI dhs-BI requested a review from aaronpk February 3, 2025 22:43
@aaronpk
Copy link
Collaborator

aaronpk commented Feb 3, 2025

I believe JIT should still be allowed, since it's possible a newly created user may log in before the pre-provisioning task has run.

deansaxe and others added 2 commits February 3, 2025 17:54
Accepting edits.

Co-authored-by: Aaron Parecki <aaron@parecki.com>
@dhs-BI
Copy link
Author

dhs-BI commented Feb 4, 2025

@aaronpk please review again. I have addressed your earlier comments.

@aaronpk aaronpk merged commit 0a613e8 into main Feb 4, 2025
@aaronpk aaronpk deleted the dhs-BI-rotate-tables branch February 4, 2025 02:23
@dickhardt
Copy link
Contributor

IL2 - should JIT be allowed? This is in conflict with pre-provisioning/deprovisioning.

This will be an app / enterprise specific policy

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants