<h2>Machine identity Recommendations</h2><br/><div style="overflow-x:auto"><h1 style="margin: 18pt 0cm 4pt; line-height: 30.933332px; break-after: avoid; font-size: 20pt; font-family: 'Aptos Display', sans-serif; color: rgb(15, 71, 97); font-weight: normal; font-style: normal; text-align: start;"><span style="font-family: 'times new roman', times;">Machine Identity Console </span></h1> <p style="margin-right: 0cm; margin-left: 0cm; font-size: medium; font-family: 'Times New Roman', serif; color: rgb(0, 0, 0); font-style: normal; font-weight: 400; text-align: start;"><span style="font-family: 'times new roman', times;"><span class="normaltextrun">Machine Identity Console allows </span><span class="normaltextrun">Admin & Integration owner</span><span class="normaltextrun"> to manage Machine identities, which identify, authenticate, and authorize applications, workloads, <span style="outline: transparent solid 1px; font-variant-ligatures: none !important;">API’s,</span></span><span style="font-variant-ligatures: none !important;"> bots, and automated systems.</span><span class="eop"> </span></span></p> <p style="margin-right: 0cm; margin-left: 0cm; font-size: medium; font-family: 'Times New Roman', serif; color: rgb(0, 0, 0); font-style: normal; font-weight: 400; text-align: start;"><span style="font-family: 'times new roman', times;"><span class="normaltextrun"><span style="color: black; background: white;">Security score and findings</span></span><span class="normaltextrun"><span style="color: black; background: white;"> in Machine identity console</span></span><span class="normaltextrun"><span style="color: black; background: white;"> </span>is based on the usage and method of</span><span class="normaltextrun"><span style="color: black; background: white;"> authenticating</span></span><span class="normaltextrun">machine identities to help identify higher risk identities so </span><span class="normaltextrun"><span style="color: black; background: white;">admins</span></span><span class="normaltextrun"><span style="color: black; background: white;"> can take the necessary preventative actions</span> for them.</span><span class="eop"><span style="color: rgb(209, 52, 56);"><span style="white-space: pre-wrap;"> </span></span></span></span></p> <p style="margin: 0cm 0cm 8pt; line-height: 18.559999px; font-size: medium; font-family: Aptos, sans-serif; color: rgb(0, 0, 0); font-style: normal; font-weight: 400; text-align: start; white-space: pre-wrap; overflow-wrap: break-word;"><span style="font-variant-ligatures: none !important; font-family: 'times new roman', times;">The Machine identity security score is based on the following findings: </span></p> <ul style="margin-top: 0px; margin-bottom: 10.65625px; list-style-position: inside;"><li style="margin: 0cm 0cm 0cm 0px; line-height: 116%; font-size: 12pt; font-family: 'times new roman', times;"><span style="font-family: 'times new roman', times;">Accounts with no login for 100 days</span></li><li style="margin: 0cm 0cm 0cm 0px; line-height: 116%; font-size: 12pt; font-family: 'times new roman', times;"><span style="font-family: 'times new roman', times;">Accounts using Basic Authentication</span></li><li style="margin: 0cm 0cm 0cm 0px; line-height: 116%; font-size: 12pt; font-family: 'times new roman', times;"><span style="font-family: 'times new roman', times;">Integration accounts with Web Service Access disabled</span></li><li style="margin: 0cm 0cm 8pt 0px; line-height: 116%; font-size: 12pt; font-family: 'times new roman', times;"><span style="font-family: 'times new roman', times;">Accounts performing both UI and API logins</span></li></ul> <h1 style="margin: 18pt 0cm 4pt; line-height: 30.933332px; break-after: avoid; font-size: 20pt; font-family: 'Aptos Display', sans-serif; color: rgb(15, 71, 97); font-weight: normal; font-style: normal; text-align: start;"><span style="font-family: 'times new roman', times;">The recommended actions for each finding are as follows:</span></h1> <p style="margin: 0cm 0cm 8pt; line-height: 18.559999px; font-size: medium; font-family: Aptos, sans-serif; color: rgb(0, 0, 0); font-style: normal; font-weight: 400; text-align: start;"><span style="font-family: 'times new roman', times;"><strong>Accounts with no login for 100 days</strong></span></p> <p style="margin: 0cm 0cm 8pt; line-height: 18.559999px; font-size: medium; font-family: Aptos, sans-serif; color: rgb(0, 0, 0); font-style: normal; font-weight: 400; text-align: start;"><span style="font-family: 'times new roman', times;">This account that has not signed in for 100 days or more. Consider deactivating the account to reduce the risk.</span></p> <p style="margin: 0cm 0cm 8pt; line-height: 18.559999px; font-size: medium; font-family: Aptos, sans-serif; color: rgb(0, 0, 0); font-style: normal; font-weight: 400; text-align: start;"><span style="font-family: 'times new roman', times;">To make the account inactive, follow these steps: </span></p> <ul style="margin-top: 0px; margin-bottom: 10.65625px; list-style-position: inside;"><li style="margin: 0cm 0cm 0cm 0px; line-height: 116%; font-size: 12pt; font-family: 'times new roman', times;"><span style="font-family: 'times new roman', times;">Click the Machine identity link to view the user record.</span></li><li style="margin: 0cm 0cm 0cm 0px; line-height: 116%; font-size: 12pt; font-family: 'times new roman', times;"><span style="font-family: 'times new roman', times;">Uncheck the Active checkbox.</span></li><li style="margin: 0cm 0cm 8pt 0px; line-height: 116%; font-size: 12pt; font-family: 'times new roman', times;"><span style="font-family: 'times new roman', times;">Update the record.</span></li></ul> <p style="margin: 0cm 0cm 8pt; line-height: 18.559999px; font-size: medium; font-family: Aptos, sans-serif; color: rgb(0, 0, 0); font-style: normal; font-weight: 400; text-align: start;"> </p> <p style="margin: 0cm 0cm 8pt; line-height: 18.559999px; font-size: medium; font-family: Aptos, sans-serif; color: rgb(0, 0, 0); font-style: normal; font-weight: 400; text-align: start;"><span style="font-family: 'times new roman', times;"><strong>Accounts using Basic Authentication</strong></span></p> <p style="margin: 0cm 0cm 8pt; line-height: 18.559999px; font-size: medium; font-family: Aptos, sans-serif; color: rgb(0, 0, 0); font-style: normal; font-weight: 400; text-align: start;"><span style="font-family: 'times new roman', times;">Basic Auth is not the most recommended authentication mechanism. ServiceNow supports alternative, more secure methods of authentication. It is recommended upgrading your machine identity to a more secure method.</span></p> <ul style="margin-top: 0px; margin-bottom: 10.65625px; list-style-position: inside;"><li style="margin: 0cm 0cm 0cm 0px; line-height: 116%; font-size: 12pt; font-family: 'times new roman', times;"><span style="font-family: 'times new roman', times;">Refer to the <a href="https://www.servicenow.com/docs/csh?topicname=inbound-integrations.html&version=latest" target="_blank" rel="noopener noreferrer">Inbound Integration</a> documentation. Once you're familiar, explore the new Inbound Integration experience [Machine identity Console tab: Inbound Integrations].</span></li><li style="margin: 0cm 0cm 8pt 0px; line-height: 116%; font-size: 12pt; font-family: 'times new roman', times;"><span style="font-family: 'times new roman', times;">Use the <a href="https://www.servicenow.com/docs/csh?topicname=certificate-based-authentication.html&version=latest" target="_blank" rel="noopener noreferrer">Certificated Based Authentication</a> as an alternate authentication option.</span></li></ul> <p style="margin: 0cm 0cm 8pt; line-height: 18.559999px; font-size: medium; font-family: Aptos, sans-serif; color: rgb(0, 0, 0); font-style: normal; font-weight: 400; text-align: start;"><span style="font-family: 'times new roman', times;">To learn more about why Basic Auth is not recommended, read section 4 in the <a style="color: rgb(150, 96, 125); text-decoration: underline;" href="https://orca.security/resources/blog/owasp-non-human-identities-top-10/">OWASP Non-Human Identities</a>article.</span></p> <p style="margin: 0cm 0cm 8pt; line-height: 18.559999px; font-size: medium; font-family: Aptos, sans-serif; color: rgb(0, 0, 0); font-style: normal; font-weight: 400; text-align: start;"> </p> <p style="margin: 0cm 0cm 8pt; line-height: 18.559999px; font-size: medium; font-family: Aptos, sans-serif; color: rgb(0, 0, 0); font-style: normal; font-weight: 400; text-align: start;"><span style="font-family: 'times new roman', times;"><strong>Integration accounts with Web Service Access disabled</strong></span></p> <p style="margin: 0cm 0cm 8pt; line-height: 18.559999px; font-size: medium; font-family: Aptos, sans-serif; color: rgb(0, 0, 0); font-style: normal; font-weight: 400; text-align: start;"><span style="font-family: 'times new roman', times;">This account that has Web Service Access disabled. Consider enabling the Web Service Access for the account to reduce the risk.</span><br /><br /><span style="font-family: 'times new roman', times;">To make the account inactive, follow these steps: </span></p> <ul style="margin-top: 0px; margin-bottom: 10.65625px; list-style-position: inside;"><li style="margin: 0cm 0cm 0cm 0px; line-height: 116%; font-size: 12pt; font-family: 'times new roman', times;"><span style="font-family: 'times new roman', times;">Click the Machine identity link to view the user record.</span></li><li style="margin: 0cm 0cm 0cm 0px; line-height: 116%; font-size: 12pt; font-family: 'times new roman', times;"><span style="font-family: 'times new roman', times;">Set the <strong>Identity type</strong> = <strong>Machine </strong>in sys_user record (This will automatically check the Web Service Access checkbox).</span></li><li style="margin: 0cm 0cm 8pt 0px; line-height: 116%; font-size: 12pt; font-family: 'times new roman', times;"><span style="font-family: 'times new roman', times;">Update the record.</span></li></ul> <p style="margin: 0cm 0cm 8pt; line-height: 18.559999px; font-size: medium; font-family: Aptos, sans-serif; color: rgb(0, 0, 0); font-style: normal; font-weight: 400; text-align: start;"><span style="font-family: 'times new roman', times;"><strong> </strong></span></p> <p style="margin: 0cm 0cm 8pt; line-height: 18.559999px; font-size: medium; font-family: Aptos, sans-serif; color: rgb(0, 0, 0); font-style: normal; font-weight: 400; text-align: start;"><span style="font-family: 'times new roman', times;"><strong>Accounts performing both UI and API logins</strong></span></p> <p style="margin: 0cm 0cm 8pt; line-height: 18.559999px; font-size: medium; font-family: Aptos, sans-serif; color: rgb(0, 0, 0); font-style: normal; font-weight: 400; text-align: start;"><span style="font-family: 'times new roman', times;">Account that is performing UI login but marked for integration. Consider creating a separate account for UI logins and use this account only for integration, and vice-versa.</span></p> <p style="margin: 0cm 0cm 8pt; line-height: 18.559999px; font-size: medium; font-family: Aptos, sans-serif; color: rgb(0, 0, 0); font-style: normal; font-weight: 400; text-align: start;"> </p></div>