Property |
Description |
Employee |
Employee that uses this user account. An employee is already entered if the user account was generated by an account definition. If you create the user account manually, you can select an employee in the menu. If you are using automatic employee assignment, an associated employee is found and added to the user account when you save the user account.
For a user account with an identity of type Organizational identity, Personalized administrator identity, Sponsored identity, Shared identity or Service identity, you can create a new employee.
To do this, click Next to the input field and enter the required employee master data. The login data required depends on the selected identity type. |
Account Definition |
Account definition through which the user account was created. Use the account definition to automatically fill user account master data and to specify a manage level for the user account. The One Identity Manager finds the IT operating data of the assigned employee and enters it in the corresponding fields in the user account.
NOTE: The account definition cannot be changed once the user account has been saved. |
Manage Level |
Manage level of the user account. Select a manage level from the menu. You can only specify the manage level if you have also entered an account definition. All manage levels of the selected account definition are available in the menu. |
Account Name |
Template calculated value that is set to user’s Name. |
User Account is Blocked |
Check this check box if user account is blocked. |
Block status reason |
Optionally select the reason why the user is account is blocked.
NOTE: Block status reason is a defined list of values and can be customized in the Designer |
Block status comment |
Optional comment on why the user account is blocked. |
First Name |
The first name of the user. If you have assigned an account definition, the input field is automatically filled with the manage level. |
Last Name |
The last name of the user. If you have assigned an account definition, the input field is automatically filled with the manage level. |
Middle Name |
The middle name of the user. If you have assigned an account definition, the input field is automatically filled with the manage level. |
Gender |
Select the gender of the user. If you have assigned an account definition, the input field is automatically filled with the manage level. |
UserExternalID |
Read only field. The user’s external id is created in Epic and synchronized back in to OneIM database. |
Community ID |
Read only field. The user’s community id is created in Epic and synchronized back in to OneIM database. |
Internal ID |
Read only field. The user’s internal id is created in Epic and synchronized back in to OneIM database. |
System Login ID |
The user’s system login id. |
Display Name |
Template calculated value that is set to user’s Name. |
Name |
Template calculated value that is set to user’s Name. Once synchronization runs for the user, the user’s External ID is appended to the name. |
User Alias |
The user’s alias. |
User Notes |
Any notes about the user. |
Start Date |
The date on which the user becomes active. On object creation, if you have assigned an account definition, the input field is automatically filled with the manage level. |
End Date |
The date at which the user becomes inactive. If you have assigned an account definition, the input field is automatically filled with the manage level. |
Contact Comment |
Contact comment for the user. This is a Template calculated value.
|
Primary Manager |
The user’s primary manager.
NOTE: Primary manager can be chosen only from the list of managers assigned to the user |
Category |
Categories for the inheritance |
EMPTemplate can be inherited |
Specifies whether the user can inherit EMPTemplate through Base tree inheritance via Organizations, Business Roles and ITShop. |
SubTemplate can be inherited |
Specifies whether the user can inherit SubTemplate through Base tree inheritance via Organizations, Business Roles and ITShop. |
IsTemplateUpdateDisabled |
Specifies whether the EMPTemplate and SubTemplate can be inherited through SecurityMatrix approach. Select this option if EMPTemplate and SubTemplate inheritance should NOT happen for the user.
NOTE: Only applicable for SecurityMatrix inheritance. |
DoNotSync |
Specifies whether the user information should NOT be synchronized from the target Epic system in to One Identity Manager. Select this option if user information should NOT be synchronized. |
Privileged User Account |
Specifies whether this account is a Privileged User Account.
NOTE: This option is only for governance. Setting this option does not have any impact of the target Epic system. |
User account is disabled |
This is a Template calculated value. Specifies whether the user account is disabled.
NOTE: The template can be customized in the Designer according to customer requirements |
EMP SER Link |
This field specifies the link between the Epic EMP User record and SER record.
NOTE: The prerequisite for provisioning this field is to have the LinkedProviderIDType to be configured in the respective targets synchronization project. |