Configure client session access role
The Embedded Session Role Configuration (Client Access Role configuration) record is created by default, which included removal of admin and security admin roles (high privilege roles) for the users using the UI components on the third-party portals.
Before you begin
Role required: admin
Procedure
Navigate to All > Client Access > Client Access Role Configurations.
Select Embedded Session Role Configuration.
Image omitted: embedded-session-role.png
Embedded Session
Embedded Session
**Note:** The **Embedded Session Role Configuration** record is created by default to remove admin and security admin roles \(high privilege roles\) for the users for the embedded session.
The details for the configuration is displayed. By default, the configuration ensures that high privilege roles such as **admin** and **security\_admin** are removed in the Embedded Session.
Image omitted: embedded-session-role-record.png
Configuration record
Configuration record
You can add more users to the list based on your requirement.
Use the information icon to open the policy.
The policy (Remove high privilege roles Policy) has the following details:
- Policy Inputs: Embedded Session- the user-specific filter criteria that is used to remove the configured roles.
Image omitted: embedded-session-role-record-input.png
Policy input record
Policy input record
- **Policy Conditions**: Remove high privilege roles in Embedded Session- the condition validates to true to remove the high privilege roles that are added for the configuration.
Image omitted: embedded-session-role-record-role-true.png
Condition set to true
Condition set to true
When the user is accessing the ServiceNow components in the third-party portal, based the above configurations, high- privilege roles are removed for that embedded session.
You can also add more roles that needs to be removed to this **Embedded Session Role Configuration** record.