Enter the following main data of a customer node:
Table 70: General main data of a customer node
IT Shop node |
IT Shop structure name. |
Internal name |
Internal IT Shop structure name. |
IT Shop information |
Labels the IT Shop structure as customer node. In the menu, select Customers.
The menu is only displayed when you insert a new IT Shop structure. |
Role type |
Not relevant |
Shelf template |
N/A. |
Parent IT Shop node |
Parent IT Shop nodes in the IT Shop hierarchy. Select the shop to which the customer node will be added. Only one customer node is allowed per shop. |
Full name |
Full identifier of the customer node. |
Location |
N/A. |
Department |
N/A. |
Cost center |
N/A. |
Owner |
N/A. |
Deputy manager |
N/A. |
Attestors |
N/A. |
Description |
Text field for additional explanation. |
Dynamic roles not allowed |
Specifies whether a dynamic role can be created for the customer node. |
Related topics
Additional company-specific information. Use the Designer to customize display names, formats, and templates for the input fields.
Add an identity that is authorized to make requests for the shop to the customer node. You have two possible ways of doing this. Identities can be assigned to a customer node either directly or through a dynamic role.
IMPORTANT:If a shop contains a large number of customers, the calculations in the
IT Shop can cause a heavy load on the
DBQueue Processor and therefore on the database server, as well.
Never assign more than 30,000 identities to a customer node.
To assign identities directly to a custom node
-
In the Manager, select the IT Shop > IT Shop > <shop> > Customers category or the IT Shop > IT Shop > <shopping center> > <shop> > Customers category.
-
Select the Assign identities task.
In the Add assignments pane, assign the identities authorized to make requests.
TIP: In the Remove assignments pane, you can remove assigned identities.
To remove an assignment
- Save the changes.
If an identity is removed from a customer node, all pending requests for this identity are canceled.
Related topics
Add an identity that is authorized to make requests for the shop to the customer node. You have two possible ways of doing this. Identities can be assigned to a customer node either directly or through a dynamic role.
NOTE: Create dynamic role is only available for customer nodes that do not have Dynamic roles not allowed set.
IMPORTANT:If a shop contains a large number of customers, the calculations in the
IT Shop can cause a heavy load on the
DBQueue Processor and therefore on the database server, as well.
Formulate the condition for the dynamic role so that no more than 30,000 identities are found.
To create a dynamic role
-
In the Manager, select the IT Shop > IT Shop > <shop> > Customers category or the IT Shop > IT Shop > <shopping center> > <shop> > Customers category.
-
Select the Create dynamic role task.
-
Enter the required main data.
- Save the changes.
To edit a dynamic role
-
In the Manager, select the IT Shop > IT Shop > <shop> > Customers category or the IT Shop > IT Shop > <shopping center> > <shop> > Customers category.
-
Select the Entitled customers overview task.
-
Select the Dynamic roles form element and click on the dynamic role.
-
Select the Change main data task and edit the dynamic role's main data.
- Save the changes.
For more information about dynamic roles, see the One Identity Manager Identity Management Base Module Administration Guide. The following features apply to dynamic roles for customer nodes:
Table 71: Properties of a customer node dynamic role
IT Shop node |
This data is initialized with selected customer nodes. If the identities meet the dynamic role conditions, they are added to this customer node. |
Object class |
Employee |
Dynamic role |
The dynamic role name is made up of the object class and the full name of the IT Shop node by default. |
Calculation schedule |
Schedule for calculating dynamic roles. Identities with request permissions for the shop are determined regularly at the times specified in the schedule.
In the default installation of One Identity Manager, the Dynamic roles check schedule is already defined. All dynamic role memberships are checked using this schedule and recalculation operations are sent to the DBQueue Processor if necessary. Use the Designer to customize schedules or set up new ones to meet your requirements. For more information, see the One Identity Manager Operational Guide. |
To delete a dynamic role
-
In the Manager, select the IT Shop > IT Shop > <shop> > Customers category or the IT Shop > IT Shop > <shopping center> > <shop> > Customers category.
-
Select the Entitled customers overview task.
-
Select the Dynamic roles form element and click on the dynamic role.
-
In the Manager's toolbar, click .
- Confirm the security prompt with Yes.
Related topics