Installed modules: | Business Roles Module |
When you use the Business role membership attestation default attestation policy and have set up attestation policies with the Business role membership attestation default attestation procedure, you can configure automatic removal of business roles through the QER | Attestation | AutoRemovalScope | RoleMembership configuration parameter. After attestation approval has been denied, One Identity Manager checks which type of assignment was used for the user account to become a member in the business role.
Configuration parameter |
Effect when set |
---|---|
QER | Attestation | AutoRemovalScope | RoleMembership | RemoveDirectRole |
The employee's secondary membership in the business role is removed. This removes all indirect assignments obtained by the employee through this business role. Membership in dynamic roles is not removed by this. |
QER | Attestation | AutoRemovalScope | RoleMembership | RemoveRequestedRole |
If the employee requested the business role through the IT Shop, the request is canceled or unsubscribed. This removes all indirect assignments obtained by the employee through this business role. Set the desired behavior in the QER | Attestation | AutoRemovalScope | PWOMethodName configuration parameter. For more information, see Default attestation and withdrawal of entitlements. |
QER | Attestation | AutoRemovalScope | RoleMembership | RemoveDelegatedRole |
If the business role was delegated to the employee, delegation is canceled or unsubscribed. This removes all indirect assignments obtained by the employee through this business role. Set the desired behavior in the QER | Attestation | AutoRemovalScope | PWOMethodName configuration parameter. For more information, see Default attestation and withdrawal of entitlements. |
QER | Attestation | AutoRemovalScope | RoleMembership | RemoveDynamicRole |
The employee is excluded from the business role's dynamic role. This removes all indirect assignments obtained by the employee through this business role. This does not remove memberships in the business role that were created in another way. |