Account discovery and control enables enterprise organizations to identify and manage Postman usage within their corporate networks. This feature provides visibility into user activity and enforcement capabilities to ensure compliance with organizational security policies.
Enterprise organizations require strong control over which Postman accounts their users can access from corporate networks and devices. Organizations use Cloud Access Security Brokers (CASBs), firewalls, and virtual private networks to manage and monitor network access, but currently lack standardized guidance for controlling Postman usage.
Common challenges with account discovery and control include:
While features like domain capture ensure users with corporate email addresses are directed to their corporate Postman instance, there’s currently no easy way to prevent users from registering with personal email addresses.
Learn more about how Postman Enterprise’s account discovery and control features can help your organization manage Postman usage and ensure compliance with security policies. Also check out the use cases to see how account discovery and control can be applied in different scenarios, such as blocking personal accounts, managing multiple teams, and considerations for firewall bypass situations.
Account discovery identifies Postman usage within corporate managed environments. This process:
Once accounts are identified in controlled environments, account control provides options to manage user access:
When users are blocked by account control, they see this message: “Your company enforces usage of Postman to only approved accounts.”
Account discovery works through an industry-standard, organization-specific header system that integrates with CASBs and network management tools. The general process is as follows:
Organizations implement account discovery by adding a header with the following specifications to all HTTP(S) traffic to Postman domains:
x-pm-network-tagpostman.co, postman.com, and *.getpostman.comThis approach is supported by major CASB vendors and used by leading SaaS applications.
Account discovery and control can be used in various scenarios to enhance security and compliance.
When a user accesses Postman from a corporate network:
For organizations with multiple teams where domain capture across teams isn’t applicable, the following process can be used:
Some organizations configure corporate laptops to always route traffic through corporate firewalls, but not all do. When users bypass firewalls, account discovery can still identify and record their activity, but enforcement may be limited. In these cases, the following considerations apply: