Chat now with support
Chat with Support

Active Roles 8.1.1 - Administration Guide

Introduction Getting started Rule-based administrative views Role-based administration
Access Templates as administrative roles Access Template management tasks Examples of use Deployment considerations Windows claims-based access rules
Rule-based autoprovisioning and deprovisioning
Provisioning Policy Objects Deprovisioning Policy Objects How Policy Objects work Policy Object management tasks Policy configuration tasks
Property Generation and Validation User Logon Name Generation Group Membership AutoProvisioning Exchange Mailbox AutoProvisioning AutoProvisioning in SaaS products OneDrive Provisioning Home Folder AutoProvisioning Script Execution Microsoft 365 and Azure Tenant Selection E-mail Alias Generation User Account Deprovisioning Office 365 Licenses Retention Group Membership Removal Exchange Mailbox Deprovisioning Home Folder Deprovisioning User Account Relocation User Account Permanent Deletion Group Object Deprovisioning Group Object Relocation Group Object Permanent Deletion Notification Distribution Report Distribution
Deployment considerations Checking for policy compliance Deprovisioning users or groups Restoring deprovisioned users or groups Container Deletion Prevention policy Picture management rules Policy extensions
Using rule-based and role-based tools for granular administration Workflows
Key workflow features and definitions About workflow processes Workflow processing overview Workflow activities overview Configuring a workflow
Creating a workflow definition for a workflow Configuring workflow start conditions Configuring workflow parameters Adding activities to a workflow Configure an Approval activity Configuring a Notification activity Configuring a Script activity Configuring an If-Else activity Configuring a Stop/Break activity Configuring an Add Report Section activity Configuring a Search activity Configuring CRUD activities Configuring a Save Object Properties activity Configuring a Modify Requested Changes activity Enabling or disabling an activity Enabling or disabling a workflow Using the initialization script
Approval workflow Email-based approval Automation workflow Activity extensions
Temporal Group Memberships Group Family Dynamic groups Active Roles Reporting Management History Entitlement profile Recycle Bin AD LDS data management One Identity Starling Join and configuration through Active Roles Managing One Identity Starling Connect Configuring linked mailboxes with Exchange Resource Forest Management Configuring remote mailboxes for on-premises users Azure AD, Microsoft 365, and Exchange Online Management
Configuring Active Roles to manage Hybrid AD objects Managing Hybrid AD users
Creating a new Azure AD user with the Web Interface Viewing or updating the Azure AD user properties with the Web Interface Viewing or modifying the manager of a hybrid Azure user Disabling an Azure AD user Enabling an Azure AD user Deprovisioning of an Azure AD user Undo deprovisioning of an Azure AD user Adding an Azure AD user to a group Removing an Azure AD user from a group View the change history and user activity for an Azure AD user Deleting an Azure AD user with the Web Interface Creating a new hybrid Azure user with the Active Roles Web Interface Converting an on-premises user with an Exchange mailbox to a hybrid Azure user Licensing a hybrid Azure user for an Exchange Online mailbox Viewing or modifying the Exchange Online properties of a hybrid Azure user Creating a new Azure AD user with Management Shell Updating the Azure AD user properties with the Management Shell Viewing the Azure AD user properties with the Management Shell Delete an Azure AD user with the Management Shell Assigning Microsoft 365 licenses to new hybrid users Assigning Microsoft 365 licenses to existing hybrid users Modifying or removing Microsoft 365 licenses assigned to hybrid users Updating Microsoft 365 licenses display names
Unified provisioning policy for Azure M365 Tenant Selection, Microsoft 365 License Selection, Microsoft 365 Roles Selection, and OneDrive provisioning Microsoft 365 roles management for hybrid environment users Managing Microsoft 365 contacts Managing Hybrid AD groups Managing Microsoft 365 Groups Managing cloud-only distribution groups Managing cloud-only dynamic distribution groups Managing Azure security groups Managing cloud-only Azure users Managing cloud-only Azure guest users Managing cloud-only Azure contacts Changes to Active Roles policies for cloud-only Azure objects Managing room mailboxes Managing cloud-only shared mailboxes
Modern Authentication Managing the configuration of Active Roles
Connecting to the Administration Service Managed domains Using unmanaged domains Evaluating product usage Creating and using virtual attributes Examining client sessions Monitoring performance Customizing the Console Using Configuration Center Changing the Active Roles Admin account Enabling or disabling diagnostic logs Active Roles Log Viewer
SQL Server replication Using regular expressions Administrative Template Communication ports Active Roles and supported Azure environments Integrating Active Roles with other products and services Active Roles Language Pack Active Roles Diagnostic Tools Active Roles Add-on Manager

Examining user activity

The Change Tracking log also allows you to examine the changes that a given user made to directory data, that is, the management activity of the user. The management activity retention time depends on the Change Tracking log configuration: For more information, see Change-tracking policy.

To see what changes were made by a given user, right-click the user object in the Active Roles Console and click User Activity.

By default, the User Activity window only displays basic options. You can display more choices by clicking the plus sign (+) in the top-left corner, next to the first column heading.

In the User Activity window, you can find the following information:

  • Name: The name of the object for which you are examining change history.

  • Requested: The date and time that the changes were requested.

  • Completed: The date and time that the changes were applied.

  • Properties: The properties of the object that were changed, including information about the changed property values.

  • Status: Indicates whether the requested changes are applied (status COMPLETED) or waiting for approval (status PENDING).

The window also includes the same additional sections as the Change History window. For more information, see Viewing change history.

Entitlement profile

The entitlement profile is a list of entitlements, each of which represents authorization to access, use or manage a particular information resource. A resource could be a single object in the directory, such as a user, group, contact or computer object, or it could be a server-based resource, such as an Exchange mailbox, user home folder, web application or network file share. In case of a server-based resource, entitlement normally takes the form of user attributes or stems from membership in a certain group. In case of a directory object, entitlement refers to the manager or owner rights on that object.

Active Roles provides the ability to view the entitlement profile of any given user, both in the Active Roles Console and Web Interface. The entitlement profile is implemented as a configurable report that displays information about resources to which a given user is entitled. Configuration of the entitlement profile specifies what resources are to be listed and what information about each resource is to be displayed in the report. Active Roles provides effective controls to manage configuration of the entitlement profile.

A user’s entitlement profile is essentially a list of information resources to which the user is entitled. The resource can be one of the following:

  • A personal resource, such as the user’s mailbox, home folder, account enabled for Office Communications Server, or Unix-enabled account.

  • A shared, network-based resource, such as a web application or network file share, that the user has permission to access.

  • A managed resource, such as a group or distribution list, for which the user is responsible as the manager or owner.

The way in which a user gets entitled to a given resource depends upon the type of the resource:

  • For a personal resource, entitlement takes the form of certain attributes of the user’s account in the directory.

  • For a shared resource, entitlement is granted by adding the user to a certain security group in Active Directory.

  • For a managed resource, entitlement is granted by assigning the manager or owner role for a certain object in Active Directory.

The building of a user’s entitlement profile is done by applying entitlement rules to the entitlement target objects specific to that user. If a given entitlement target object matches the entitlement rules for a particular resource, then the user is regarded as entitled to the resource and information about that resource appears in the entitlement profile. The entitlement target object can be one of the following:

  • The user’s account in Active Directory. This object is used to discover the personal resources to which the user is entitled.

  • An Active Directory group of which the user is a member. This object is used to discover the shared resources to which the user is entitled.

  • An Active Directory object for which the user is assigned as the manager or owner. This object is used to discover the managed resources to which the user is entitled.

Active Roles stores the entitlement rules in configuration objects called entitlement profile specifiers. These objects are essential to the process of building and presenting the entitlement profile.

About entitlement profile specifiers

In Active Roles, entitlement profile specifiers are configuration objects that govern the process of building and presenting the entitlement profile. Each specifier holds information about a single resource that allows Active Roles to determine whether a given user is entitled to the resource and, if the user appears to be entitled, what information about that resource to include in the user’s entitlement profile.

An entitlement profile specifier holds the following information:

  • Entitlement Type: Specifies a way in which a user gets entitled to the resource.

  • Entitlement Rules: Provide a way to determine whether a given user is entitled to the resource.

  • Resource Display: Specifies how to represent the resource in the entitlement profile.

The following topics elaborate on each of these information blocks.

Entitlement type

The entitlement type setting is basically intended to determine the entitlement target object—the object to which Active Roles applies the entitlement rules when building the entitlement profile. Entitlement types can be classified by how a user’s entitlement to a resource is configured:

  • Personal resource entitlement: Configured by setting certain attribute of the user’s account itself. In this case, the user’s account plays the role of the entitlement target object.

  • Shared resource entitlement: Configured by adding the user to a certain security group. In this case, the group plays the role of the entitlement target object.

  • Managed resource entitlement: Configured by assigning the user to the manager or owner role for a certain object. In this case, the object managed or owned by the user plays the role of the entitlement target object.

The following table summarizes the types of entitlement.

Table 93: Types of entitlement

Type

Configuration

Target Object

Personal resource entitlement

The user’s account has certain resource-specific attributes set in the directory.

The user’s account

Shared resource entitlement

The user’s account belongs to a certain security group in Active Directory.

The user’s group

Managed resource entitlement

The user’s account is specified as the primary owner (manager) or a secondary owner of a certain object in the directory.

The object managed or owned by the user

Related Documents

The document was helpful.

Select Rating

I easily found the information I needed.

Select Rating