May 24' Store Release: What's new for ITOM Visibility & Cloud Accelerate
afternoon or good evening everyone and welcome to a new edition of our live on service now uh webinar Series today we're going to talk about what's new in itm visibility and itm Cloud accelerate for the Q2 2024 release um as a matter of fact we know that everyone here is going to be willing to know more about what we recently released so that the new features and new enhancements can help you succeed in uh many of your business use cases as I just said this session is part of the live on service now webinar series which is an interactive event series that is going to help you with the implementation deployment and adoption um of our solutions to really eventually achieve value in a faster way and you can uh see the schedule by just kinding this QR code uh right here and you will definitely be prompted to the whole series and even at the end of uh this event we're going to make sure to share this slide again now if you housekeeping items for today's session please make sure that everyone is muted and uh please also make sure to use the Q&A feature if you want to ask questions and uh we're going to have a few polls so please make sure to engage as you usually do in these sessions this session is also being recorded and will be shared with the uh service now Community um and also it will be available on YouTube and also after the session ends you'll be prompted to fill out a short survey so please please make sure that you fill that out you share feedback with us so we know how to improve constantly these sessions now a quick introduction for those of you that don't know me my name is John Mar deluigi I'm part of the outbound product management team for item covering visibility and cloud accelery and uh we are right now with my peers in our team leading a series of workshops that are worldwide we covered already 16 Series this year um we've interacted with many of views in real life we brought the value of the cloud um accelerating item visibility Solutions so um it's great to also be leading these webinars so we can reach out to more and more of you but before we keep going please make sure that there's a safe harbor notice for today's session so we could potentially make forward looking statements and just so uh please be um consider that these statements could be um actually used throughout this presentation now before we even get started with the content I want to just uh test out the the audience here because yes we said that it's important to be updated on what's new with itone visibility in Cloud Accel but we really want to make sure that we understand how are you currently uh checking for updates are you looking for updates on a regular basis right after every store release or are you doing that after every family release so once every 6 months let's say so uh let's say twice a year or are you doing that once every uh year or are you still wondering uh where should you look for that so I see a few answers coming in please make sure that you drop in your ANW so we can terminate this poll this is really for us to better understand what are your needs and uh how can we help you with that I see answers coming in so please make sure that you select your options and I will end the poll in 5 seconds and that's it so if we see the results as a matter of fact we see the vast majority of you is only checking for updates after every family release followed by those that are checking after every store release and then those of you that are not sure where to find these updates and then uh few very few of you check in for once a year so this is very interesting because we this is the most important thing thing of today's presentation if you want to really be up to dat with our Innovations you need to check the store the service now store for the most upto-date store apps and if you want to look at what's new you can check the release notes in our docs in our website but especially if you subscribe to your live on service now webinar series we're going to host quarterly sessions like this one like this one for today where we actually announce what's new and uh we go through the most recent Innovation so this is a great opportunity for you to know exactly what has just uh come with the Q2 store release and uh thanks Steve uh for sharing that link because in the background we're going to have uh Steve Emerson uh which many of you might have known which is the director of alound product management for it that is going to also assist you with the questions and assist us throughout the webinar so please make sure they keep those questions coming in the Q&A box all right let's say that we can start finally to see what's new starting from the item visibility side we're going to keep the traditional agenda so we're going to go through the highlights of okay what are the major what are the other new features and enhancements and we're going to see them with a little bit more uh detail as you can see from this slide I'm not going to go through each one of these items but you can see that throughout the most recent releases there has been an incredible amount of innovation that has just been released and even with the zanadu release that is going to come up soon and this um Q2 release is part let's say of the brother zanadu release we can see that we still have a lot of innovation that we're going to cover today but even if we look at Washington Vancouver Etc all these release uh were carrying a huge amount of innovation so please make sure that you always check the most recent uh versions of your store apps and even for new store apps that may be available now let's see what are the major new features and announcement there's one that is huge and we're going to see that in a minute which is the um the Acme support in certificate Inventory management I'm not going to uh waste time on that because we have a dedicated session whereas for other new features and enhancements yes we still have uh certificate Inventory management um new uh features and enhancements which is the ability to discover Java key stores and uh Windows certificate stores uh basically the you be now finally able to discover Java and windows certificates on Windows and Linux machines uh which increases hugely the uh amount of uh certificate discovery um use cases for the certificate Inventory management app and then we are also uh supporting the discovery of certificates that have been issued by Cloud native certificate authorities across major Cloud providers so across AWS Azure and gcp specifically so these are huge announcements in the certificate inventory and management space and then for those of you that are leveraging discovering service mapping patterns that's a very important app for you to really make sure they have the most recent pattern so that's something that you definitely need to check on your store um we introduced enhancements in the Azure Cloud Discovery in order to optimize uh the uh the cloud environment's discovery on Azure that means that specifically the virtual machine and Hardware type patterns are going to only be triggered for the service accounts uh for the active regions that means that it's a huge Improvement and the uh discovery of your Azure Cloud environments is going to be tremendously uh enhanced but now let's get into the main feature the the main new uh uh feature of this uh Q2 release for item visibility which is the Acme support now for those of you that are familiar with Acme it's essentially new protocol that has been recently introduced and is more and more adopted and uh it's been used by more and more certificate authorities or I would say supported by more and more certificate authorities so in case that you'll be leveraging any certificate Authority that is leveraging this protocol you'll be now easily able to fulfill certificate requests from any of those Casa this is huge because it's not about supporting one specific CA anymore it's about supporting any certificate Authority that supports this now we do include out of the box these support for let's encryp and and Trust uh with Acme but as we're going to see in a minute you can really support Anya that supports Acme and this is huge because you can save time and uh really reduce human error by uh fulfilling these certificate requests and really having a larger coverage in terms of use cases if we look at the fact sheet you will see that yes uh we have clarified the reason why it's important uh for us to have introduced the Acme support and all the use cases that are being enabled um you can activate it by downloading the main release of the certificate Inventory management Store app it is included with item visibility uh entitlement so make sure they have uh the either item visibility V1 or V2 or any bundle that includes item visibility such as item uh Pro or itm Ops Enterprise and here you see more details about the technical uh aspects and configurations of it but now from a broader architecture level I would like to say uh and thanks Steve for uh putting more links to this so that you you can see actually in the chat uh Steve posted two very interesting um uh resources that you should visit if we look at it from a micro perspective once you're defining your uh Casa in the certificate Inventory management app once you are defining your routing policy once you complete the DNS task then will be the AC request to the uh CA that you want to select in this case again we have outof the box support for let en Crypt and and trust but any uh certified supported Acme CA is valid and um that means the anak me power CA can be um uh included in this process so this is a really revolutionary in terms of how it works with the product now if you look at the certificate authorities once you will install the certificate Inventory management app you will see that you have entros acne and let encrypt they will be both Casa that are offered out of the box again and uh supported out of the box U because they um specifically for for the me support either way you can create new certificate authorities by clicking uh but just the bottle new from the previous interface from the previous UI but even in this case when looking at let's encrypt and um you know or a new record in general we can see that when creating a new ca we'll have an option to select Acme support this is going to make it for you very very easy to set up any Acme powered CA on your instance after having set up your Acme uh powered CA you'll be able to then proceed and create a uh credential a so this the specific credentials that you will need for that and in this case specifically we can see that yes um you will need the uh private key to be inserted and uh it's basically to call the apis when you're cre creating the uh CA account and it's actually linked to the Acme account and in this case specifically we're creating a new record then we selected as at trust as a CA type we need to insert the key ID and the m key and just uh you can notice that the for key type we can not only go for RSA but also for ecdsa and here as we can see depending on the ca type that we're selecting we can always select the Acme option and um this will be done of course as you can read here instead of the traditional username password and key store so uh again this is a really simplified operation to do then once we have set up the credentials we can create a new routing policy by leveraging the ca that has been defined beforehand in this case we are selecting in this example the entr Acme uh certificate Authority then we have a maximum validity period that that in this case we can uh set up in a custom way or for let's encrypt it will be by default for 90 days and then it will be the DNS task assignment group so we can uh decide a specific assignment group that will need to perform the DNS challenge to basically validate the domain ownership and once that is validated we'll be able to proceed with the new certificate task creation and as you can see here we the routing policy that we just created and the DNS task that have has been just created so we can actually proceed with a new certificate creation now uh please keep the questions coming in the Q&A section and in the meantime we're going to uh proceed with the second quiz for the day and I'm going to launch it now we want to better understand now that we have reviewed the Acme support for certificate inventory management if you actually want to leverage this uh capability and when do you want to do so or in case uh that you're not considering this capability what is the reason for that is an example you're currently not leveraging at me power uh CA and in case you're not leveraging the Acme power Casa by the way please feel free to answer in the Q&A box and specify why is your organization not leveraging Acme powered CA so we can have a better understanding of that I see a lot of uh answers are coming in so please make sure I'm just going to give uh other very few seconds so please insert your answer here and we can um move on I see also someone is sharing in the Q&A box right so I'm going to end the poll and um we're going to actually proceed I see that uh few organizations are still not leveraging the acne uh powered Casa but I see that uh yes there's definitely interest there of uh leveraging the uh Acme support in the uh next in in the coming future so thanks for answering now let me see okay thanks I see I see in the chat um there have been a few comments on the reasons why so we really appreciate your input and please keep the questions coming and we're going to have a dedicated Q&A section at the end of this session but again if you have any doubts please feel free to um or any questions just use the Q&A box uh for that purpose now we can proceed to see what's new in Cloud accelerate and the agenda is going to be the exact same of what we've seen until now we can see that yes we still have the uh value Evolution slide even in this case and we can see that what used to be called um the governance SK which is now the item Cloud accelerate skew has evolved quite a good bit from the initial introduction in San Diego and we are bringing yes a lot of innovation in this area it's huge the amount of innovation that we're bringing in this area and today we're going to see exactly for Q2 uh what are the major and other enhancements we're going to start from CAC that actually saw the introduction of new outof thee box catalog items and we're going to see more details about it then we do have cloud account management that has been released with its second version of uh Innovation lab release and then we have other new features and enhancements that are still very very important in this case they're all concerning cloud service catalog which is the central part of our offerings specifically we now offer a terraform connector enhancement for uh gcp so gcp templates can also be discovered with the terraform connector integration um we offer the U multi repo support so that regardless of the structure of the repositories where your infrastructure as code is residing right now we are able to discover those repositories discover your existing infrastructure that's code templates that you might have created to provision new Cloud resources and we can easily import that into CSC and create new Cog items so you don't have to reinvent the wheel this is automated and this is super easy to do now with even more support for different types of repositories and then we have also the introduction of the domain separation support for cc so for any of you that is interested in that use case yes now it's been validated is been tested and it's there and then when it comes to the Azure devops integration we have an improved selection of your mid server so you will have essentially enhanced performances when it comes to the Azure devops integration so you can see that this is huge this is going to help you tremendously in all these use cases and then when it comes to end of life or Sunset capabilities for those of you that might be entitled to the cloud inside building app this is going to be sun set and in the uh you'll need to migrate to uh the um Cloud accelerat CU whenever you have an item optimization entitlements and in this case in the migration you will lose entitlement to Cloud Insight which is now included in item Cloud cost management so let's get started with the CSC enhancements starting from the Google Cloud catalog items that are offered out of the box what does this mean we can easily offer self-service and for those of you that are familiar with employee portal this is exactly part of the employee portal experience that's why we have cloud services catalog you you'll have a dedicated section for cloud services as you can see here and we have out of the box items for AWS Azure and now cloud and on top of that we have an anible and Azure devops integration which is also in form of catalog items this means that any user will be easily accessing these calog items out of the box so you don't need to configure anything this comes out of the box and it will be essentially way e easier for any user to now order these col items um from this portal we leverage a terraform integration so if you don't have terraform don't you worry we're going to use an open source version of that and in this way it's going to be possible to really provision these resources in minutes with full control so you know who is authorized to order what and that means reduction or I would say optimization of cloud cost and optimization of performances not only in terms of system performances but also uh whoever is acting on these resources you can see now the list of color guidance is pretty comprehensive and um it's available with the CSC content pack Store app uh so whenever you're installing CSC make sure they install not only cloud services catalog but also CSC content pack store apps now for those of you that are using Innovation labs and by the way I want a thumbs up or I want to uh reply in the Q&A section if you're leveraging or if you have ever used Innovation lab because it's one of the coolest part of our store Innovation lab means essentially that you can try out the best Innovation that we offer for free in your non production environments and Cloud account management is one of these big biggest innovations that we have introduced and as a matter of fact with Q2 we have introduced huge improvements to it by um improving the interface by uh introducing new personas but you will be wondering yes but what is cloud account management is essentially a new central pain of glass from where users will be able to request for new Cloud accounts and from where approvers and provisioners will be able to uh fill U fill out those requests and U fulfill those requests as a matter of fact so that you have uh full control on your Cloud accounts and you can really manage those in the best possible way to optimize spend and to optimize resour resource consumptions now there are technical aspects to it and you can activate it again in Innovation lab so it's free of charge you'll just need uh the visibility entitlement and it's plan to be added to item Cloud accelery skew um but for now again there are no licensing implications now you'll be wondering how does this work well it's very easy we have the UI Builder we leverage the process automation designer in the future will will leverage the pace engine but essentially we have integration Hub that calls terraform which is actually uh getting the uh from the GitHub repositories the templates and then it's calling actually via direct API calls the cloud environments the uh Cloud org API and Cloud accounts apis so that that new cloud account will be automatically provisioned so the architecture is super simple the terraform they will be leveraging is open source so you don't need to worry about that and but yet this is super powerful because there are as well we're going to see in a minute proper flows proper processes that are set up there that you can essentially set up as you want so yes they are the box but you can do whatever you want to have full automation now if you miss the version one release we essentially had the requestor experience so anyone wasn't um typically the requestor would have been an engineering manager or in general a manager that was requesting for different accounts then we had an approver that was fully controlling who was entitled to get these new accounts and how were they configured and then we had the provisionary experience all these with support for AWS resources and as a matter of fact we kept that with the Innovation lab 2 release and then we have the processes and flows they were out of the box and there for you to be edited so you could have as much automation as you want now with the Innovation lab two we have introduced two new users so yes you still have the requestor and approver personas and they have as a matter of fact um you need uh two different uh profiles basically to access these two different uis but you will also have the cam admin there is going to it's actually a new renovated sort of approval uh I would say provisionary experience and then we have the certifier so yes Cloud accounts now can be um can be ATT toate you you can do attestation on your Cloud accounts what that means that for any cloud account that you discover you can actually assign a user so you'll finally have attestation so you know that exactly who is responsible for the cloud accounts and the resources that are being deployed within that so this is huge now the UI improvements have been there so um from the request or experience there is a dedicated subscription accounts uh dashboard so you can see the active suspended and closed Cloud accounts instead from the new C so cloud account management admin Persona experience we have yes new tab so it's easier to navigate through the main information the request configuration of sub subscription accounts but also ancu high with uh request in sight as been introduced when it comes to the admin experience we also have um once the admin is triggering the account provisioning flow and the actual account will be eventually provisioned not only will be brought back to a manage account but also the child accounts as you can see here will be activated and will be uh basically discovered as unmanaged accounts so this is another very important in uh enhancement that has been brought there not only the main ones but even the child accounts and when it comes to the sub subscription accounts you can go now to all the accounts so all the ones uh that have been discovered and they will be uh actually appearing under this UI and then one select one as we did here the C admin can decide whether to manage each one of these accounts and um to manage these only the AWS accounts are supported for now so they can decide the account owner and then we have the suspend experience basically and again uh if I if I was talking beforehand we said yes any account will be managed yes but for now the manage account is only available for AWS because it's still in Innovation lab release so again um The Innovation lab release is still a trial version for you so you can try it out and you can provide us with feedback and then we can go ahead uh and you can evaluate the product now another cool feature is that you can now suspend account so let's say that the account specifically has um a had the find Budget and now uh it's at the limit of the budget so they cannot have new provisioning so when we suspended account that means they're not uh it won't be possible to provision new um uh resources for that account but it will still be active and in the back end basically service control policies will be put in place on the AWS side and if you want to suspend an account actually notice that there will be an approval task uh that will be generated so that means that there needs to be an approver if you want or um if you want you can automate that step but out of the box you need an approval and you will receive an email and a task and then the designated approver as you can see from thei will determine whether to prove deny or constantly request for suspension reactivation accounts is working basically in this same way but it's just the reverse of it so even in this case you need to approve the task and uh the service control policies that have been put in place before will be removed on the AWS side now talking about the automation processes in flows these are very important because as you can see here once you log in into the process automation designer UI you have customizable flows actually processes that include flows and subflows and actions that can be changed and these include the creation reactivation and suspension processes as we can see here we have the uh in the account creation C sub subscription account creation process we have uh not only they prepare create uh workspace create account uh flows but we also have the post-provisioning action such as run Discovery and post-discovery operations and again just keep in mind that each one of these flows and subflows can be edited so you can do as much information as you want and as a matter of fact we can see that the account suspension and reactivation processes have been added to the innovational release and you can also addit these ones basically um they as you can see here they're leveraging Direct API calls to um AWS and uh to suspend and reactivate these accounts clearly then the come certified experience we also have this new capability of certifying the accounts this is Now supported for any um potential um account but what does that mean we have a dedicated uh cam certification policy that is running and we can view it actually from the CNB workspace as you can see here from this very same UI so anybody that is part in this case of the item C certified group can review each of those tasks that have been created in here we have the certification tasks and they are leveraging the uh CB data certification capability and then the come certifier can decide whether to uh certify fail or uh review the records the current cam certification policy is actually only on um aimed at certifying the ownership for each of the cloud accounts so all the discovery Cloud accounts are still supported with the c feature nowadays and this is the limitation that we do not have for the AWS accounts but the certification is certifying the ownership of these accounts as a matter of fact if we go into the uh data certification policies we can see the published policies and if we see the C certification policy here this is out of the box and this is available for the cam admin uh certifiers if we go into the subscription accounts view under cam for these users we can see that the cam admin can view the accounts that have been certified failed or pending so this is a way to enforce upstation and this is really powerful because any of these accounts can be certified in that way now right I see a lot of engagements and interest in the cmdb health space I just want to launch the last Poll for today and I'm going to do that in a second so okay I'm going to launch it now we want to better understand from you now that you've seen how cloud account management is first of all it's free and second is again in Innovation lab release so it's a really powerful way for you to really make sure that you can share your experience with us so that we can keep improving that product and especially if you have visibility entitlements you can test it out for free in your sopr environment so I would say why not right and I see a lot of you are uh putting their answers in here I see a lot of participation so I really thank you for for that and I see interesting uh preliminary results here so I'm going to end the poll in 5 seconds so please make sure you keep your questions coming in your answers coming in right it looks like okay this is very interesting I'm going to end the poll now and uh we can see that yes it's actually interesting um that uh a lot of you can't wait to try this out and otherwise you're intention to talk to your Cloud team so this is great to hear yes please make sure they talk to your Cloud team so you can collaborate on cam this going to be one of the best um and interesting features they were going to release this year so really uh breakthrough product so you absolutely need to try that out now before the next steps I want to make sure that we address and we answer any questions so is any any other question for us I see that Steve has helped um actually uh answering most of these questions so thank you for that Steve but any other last minute questions before we go into the next steps you have this opportunity to talk to the product management team so make sure you can leverage it we're not going to expose you of course all right in the meantime that you're typing there uh we're going to go through the next step so first of all if you want to meet the product management team in person and you want to learn more not only about uh cloud accelery in Cloud acceleration Concepts but of course also about item visibility we're leading a global workshop and uh it's uh we're going to cover more than 30 cities this year we've already covered about 16 and we have many more to come so please make sure that you scan these QR codes and typically we will uh try to offer these workshops they are one day each we'll try to offer them backto back so one after the other so in case you are interested in both you can absolutely uh go to both uh cities sorry to both events in your city and yes we will definitely appreciate you uh showing up to these events now um you're going to learn more about our products best practices you're going to do Hands-On experiences so these are really intended to make sure that you understand what you you're entitled to what the capabilities of our products are and how you can best use them and if you want to join our future webinars and meetups as I said before make sure that you scan this QR code here because the live on service now events are there for you and I see questions about okay what is needed to enable the is Discovery and service mapping plugin on a PDI and maybe Steve will take that on okay are we playing I can answer it John so I think there are some limitations as to what you can and cannot turn on on a PDI um I would recommend going to your developer portal because we don't control that from the product side the team that offers up the pdis controls that so they should have all the documentation available as to what you can or cannot request thanks Jim amazing thank you so much Steve for that and then uh are we planning to introduce cam for Azure and when yes so save hardboard notice we're looking into uh trying to implement that over the next uh two or three releases of course these are just rough plans but if you have a specific use case where that that's why we're uh suggesting to um definitely let us know and uh we'll try to help you out but especially if you want to suggest anything around cam we do have the idea portal so the idea portal is designed to give you the opportunity to essentially input your ideas and make sure that other companies can upvote them so if 10 different people from 10 different companies will up vote your idea that means they will be brought up straight to the product management team so that's a great idea please make sure you leverage the idea portal as well and now if you want to uh actually have access to the previous sessions of our Academy for visibility in Cloud accelerate where we discuss more in detail about the recent Innovations uh since a few of you were saying that um it's been tough to really understand where the uh Innovations are being discussed for item visibility and color accelerat well make sure they you Leverage The on demand webinars that we have hosted um this year and even before you can either access uh this link or you can just scan this QR code and you'll be prompted to the uh full list right I don't see any other questions so thank you so much Steve for supporting this webinar thanks everyone for the great interactions today uh we are super excited about these Innovations and we want you to try them out go to the store and download the most recent uh Store app versions and really uh you can use the idea portal to uh communicate with us tell us what you think about uh the products if you want to share more feedback with us and we are super excited about it so uh we are really looking forward to see you soon in our next webinar um for our what's new releases and also in General on our um live on service now uh webinars so I'm going to try we just received a request to put the link for additional webinars in the chat and that's exactly what I'm going to do so for anyone that is attending now you can you can access the chat and I just posted it there and yes uh you to be able to uh access that link I'm going to stop it here so again
https://www.youtube.com/watch?v=8UvhXqkhRrc