Employees, devices, and workdesks can inherit company resources though indirect assignment. To do this, employees, devices, and workdesks may be members of as many roles as required. Employees, devices, and workdesks obtain the necessary company resources through defined rules.
To assign company resources to roles, apply the appropriate tasks to the roles.
The following table shows the possible assignments of company resources to employees, workdesks, and devices using roles.
NOTE: Company resources are defined in the One Identity Manager modules and are not available until the modules are installed.
Assignable Company Resource | Members in Roles | |
---|---|---|
Employees | Workdesks | |
Resources |
Possible |
- |
Account definitions | Possible | |
Groups of custom target systems |
Possible (assigns to all an employee's custom defined target systems user accounts, for which group inheritance is authorized) |
- |
System entitlements of custom target systems |
Possible (assigns to all an employee's custom defined target systems user accounts, for which system entitlement inheritance is authorized) |
- |
Active Directory groups |
Possible (assigns to all an employee's Active Directory user accounts and Active Directory contacts, for which Active Directory group inheritance is authorized) |
- |
SharePoint groups |
Possible (assigns to all an employee's SharePoint user accounts for which SharePoint group inheritance is authorized) |
- |
SharePoint roles |
Possible (assigns to all an employee's SharePoint user accounts for which SharePoint role inheritance is authorized) |
- |
LDAP groups |
Possible (assigns to all an employee's LDAP user accounts for which LDAP group inheritance is authorized) |
- |
Notes groups |
Possible (assigns to all an employee's Notes user accounts for which Notes group inheritance is authorized) |
- |
SAP groups |
Possible (assigns to all an employee's SAP user accounts, in the same SAP system and for which SAP group inheritance is authorized) |
- |
SAP profiles |
Possible (assigns to all an employee's SAP user accounts, in the same SAP system and for which SAP profile inheritance is authorized) |
- |
SAP roles |
Possible (assigns to all an employee's SAP user accounts, in the same SAP system and for which SAP role inheritance is authorized) |
- |
SAP parameters |
Possible (assigns to all an employee's SAP user accounts in the same SAP system) |
- |
Structural profiles |
Possible (assigns to all an employee's SAP user accounts, in the same SAP system and for which structural profile inheritance is authorized) |
- |
BI analysis authorizations |
Possible (assigns to all an employee's BI user accounts, in the same system and for which group inheritance is authorized) |
- |
Azure Active Directory groups |
Possible (assigns to all an employee's Azure Active Directory user accounts for which Azure Active Directory group inheritance is authorized) |
- |
Azure Active Directory administrator roles |
Possible (assigns to all an employee's Azure Active Directory user accounts for which Azure Active Directory administrator role inheritance is authorized) |
- |
Azure Active Directory subscriptions |
Possible (assigns to all an employee's Azure Active Directory user accounts for which Azure Active Directory subscription inheritance is authorized) |
- |
Disabled Azure Active Directory service plans |
Possible (assigns to all an employee's Azure Active Directory user accounts for which disabled Azure Active Directory service plans inheritance is authorized) |
- |
Cloud groups |
Possible (assigns to all an employee's user accounts for which cloud group inheritance is authorized) |
- |
Cloud system entitlements |
Possible (assigns to all an employee's user accounts for which cloud system entitlement inheritance is authorized) |
- |
Unix groups |
Possible (assigns to all an employee's Unix user accounts for which Unix group inheritance is authorized) |
- |
E-Business Suite permissions |
Possible (assigns to all an employee's E-Business Suite user accounts, in the same E-Business Suite system and for which E-Business Suite group inheritance is authorized) |
- |
PAM user groups |
Possible (assigns to all an employee's PAM user accounts for which PAM group inheritance is authorized) |
- |
Google Workspace products and SKUs |
Possible (assigns to all an employee's Google Workspace user accounts, in the same customer and for which Google Workspace products and SKU inheritance is authorized) |
- |
Google Workspace groups |
Possible (assigns to all an employee's Google Workspace user accounts, in the same customer and for which Google Workspace group inheritance is authorized) |
- |
SharePoint Online groups |
Possible (assigns to all an employee's SharePoint Online user accounts for which SharePoint Online group inheritance is authorized) |
- |
SharePoint Online roles |
Possible (assigns to all an employee's SharePoint Online user accounts for which SharePoint Online role inheritance is authorized) |
- |
Office 365 groups |
Possible (assigns to all an employee's Azure Active Directory user accounts for which Office 365 group inheritance is authorized) |
- |
Exchange Online mail-enabled distribution groups |
Possible (assigns to all an employee's Exchange Online mailboxes, Exchange Online mail users and Exchange Online mail contacts for which Exchange Online mail-enabled distribution group inheritance is authorized) |
- |
System roles |
Possible |
Possible |
Subscribable reports |
Possible |
- |
Software |
Possible |
Possible |