Chatee ahora con Soporte
Chat con el soporte

Identity Manager 9.3 - Attestation Administration Guide

Attestation and recertification
One Identity Manager users for attestation Attestation base data Attestation types Attestation procedure Attestation schedules Compliance frameworks Chief approval team Attestation policy owners Standard reasons for attestation Providing terms of use for attestation Attestation policies Sample attestation Grouping attestation policies Custom mail templates for notifications Suspending attestation Automatic attestation of policy violations
Approval processes for attestation cases
Approval policies for attestations Approval workflow for attestations Selecting attestors Setting up multi-factor authentication for attestation Prevent attestation by identity awaiting attestation Automatic acceptance of attestation approvals Phases of attestation Attestation by peer group analysis Approval recommendations for attestations Managing attestation cases
Attestation sequence Default attestations Mitigating controls for attestation policies Setting up attestation in a separate database Configuration parameters for attestation

Determining attested identities as attestors

Attested identities can themselves be determined as attestors and thus influence the approval sequence. The following approval procedures can be used for this:

Related topics

Determining identities linked to user accounts as attestors

If user accounts are linked with identities, the identities can attest these user accounts.

Related topics

Determining target system managers as attestors

Target system managers are given the task of attesting system entitlements, assigned user accounts and assignments of system entitlements to hierarchical roles. All identities that are assigned to the associated application role are determined as attestors. In addition, members of all the parent application roles are determined as attestors. The following approval procedures can be used for this:

Related topics

Determining attestors via product owners

An application role for product owners can be assigned to the service items of objects that can be requested from the IT Shop. Different approval procedures can be used to determine members of this application role as attestors.

Prerequisites:

  • A service item must be assigned to the attestation objects.

    To attest Microsoft Teams teams or Microsoft Teams team memberships, a service item must be assigned to the Microsoft 365 group associated with a team.

  • There must be an application role for product owners assigned to the service item.

Related topics
Documentos relacionados

The document was helpful.

Seleccionar calificación

I easily found the information I needed.

Seleccionar calificación