Chatta subito con l'assistenza
Chat con il supporto

Identity Manager 9.3 - Administration Guide for Connecting to Microsoft Entra ID

Managing Microsoft Entra ID environments Synchronizing a Microsoft Entra ID environment
Setting up initial synchronization with a Microsoft Entra ID tenant Adjusting the synchronization configuration for Microsoft Entra ID environments Running synchronization Tasks following synchronization Troubleshooting Ignoring data error in synchronization Pausing handling of target system specific processes (Offline mode)
Managing Microsoft Entra ID user accounts and identities Managing memberships in Microsoft Entra ID groups Managing Microsoft Entra ID administrator roles assignments Managing Microsoft Entra ID subscription and Microsoft Entra ID service plan assignments
Displaying enabled and disabled Microsoft Entra ID service plans forMicrosoft Entra ID user accounts and Microsoft Entra ID groups Assigning Microsoft Entra ID subscriptions to Microsoft Entra ID user accounts Assigning disabled Microsoft Entra ID service plans to Microsoft Entra ID user accounts Inheriting Microsoft Entra ID subscriptions based on categories Inheritance of disabled Microsoft Entra ID service plans based on categories
Login credentials for Microsoft Entra ID user accounts Microsoft Entra ID role management
Microsoft Entra ID role management tenants Enabling new Microsoft Entra ID role management features Microsoft Entra ID role main data Main data of Microsoft Entra ID role settings Displaying Microsoft Entra ID role settings main data Assigning temporary access passes to Microsoft Entra ID user accounts Displaying Microsoft Entra ID scoped role assignments Displaying scoped role eligibilities for Microsoft Entra ID roles Overview of Microsoft Entra ID scoped role assignments Main data of Microsoft Entra ID scoped role assignments Managing Microsoft Entra ID scoped role assignments Adding Microsoft Entra ID scoped role assignments Editing Microsoft Entra ID scoped role assignments Deleting Microsoft Entra ID scoped role assignments Assigning Microsoft Entra ID scoped role assignments Assigning Microsoft Entra ID scoped role assignments to Microsoft Entra ID user accounts Assigning Microsoft Entra ID scoped role assignments to Microsoft Entra ID groups Assigning Microsoft Entra ID scoped role assignments to Microsoft Entra ID service principals Assigning Microsoft Entra ID system roles to scopes through role assignments Assigning Microsoft Entra ID business roles to scopes though role assignments Assigning Microsoft Entra ID organizations to scopes through role assignments Overview of Microsoft Entra ID scoped role eligibilities Main data of Microsoft Entra ID scoped role eligibilities Managing Microsoft Entra ID scoped role eligibilities Adding Microsoft Entra ID scoped role eligibilities Editing Microsoft Entra ID scoped role eligibilities Deleting Microsoft Entra ID scoped role eligibilities Assigning Microsoft Entra ID scoped role eligibilities Assigning Microsoft Entra ID scoped role eligibilities to Microsoft Entra ID user accounts Assigning Microsoft Entra ID scoped role eligibilities to Microsoft Entra ID groups Assigning Microsoft Entra ID scoped role eligibilities to Microsoft Entra ID service principals Assigning Microsoft Entra ID system roles to scopes through role eligibilities Assigning Microsoft Entra ID business roles to scopes though role eligibilities Assigning Microsoft Entra ID organizations to scopes through role eligibilities
Mapping Microsoft Entra ID objects in One Identity Manager
Microsoft Entra ID core directories Microsoft Entra ID user accounts Microsoft Entra ID user identities Microsoft Entra ID groups Microsoft Entra ID administrator roles Microsoft Entra ID administrative units Microsoft Entra ID subscriptions and Microsoft Entra ID service principals Disabled Microsoft Entra ID service plans Microsoft Entra ID app registrations and Microsoft Entra ID service principals Reports about Microsoft Entra ID objects Managing Microsoft Entra ID security attributes
Handling of Microsoft Entra ID objects in the Web Portal Recommendations for federations Basic data for managing a Microsoft Entra ID environment Troubleshooting Configuration parameters for managing a Microsoft Entra ID environment Default project template for Microsoft Entra ID Editing Microsoft Entra ID system objects Microsoft Entra ID connector settings

Assigning account definitions directly to identities

Account definitions can be assigned directly or indirectly to identities. Indirect assignment is carried out by allocating identities and account definitions in company structures, like departments, cost centers, locations, or business roles.

To react quickly to special requests, you can assign account definitions directly to identities.

To assign an account definition directly to identities

  1. In the Manager, select the Microsoft Entra ID > Basic configuration data > Account definitions > Account definitions category.

  2. Select an account definition in the result list.

  3. Select the Assign to identities task.

  4. In the Add assignments pane, add identities.

    TIP: In the Remove assignments pane, you can remove assigned identities.

    To remove an assignment

    • Select the identity and double-click .

  5. Save the changes.
Related topics

Assigning account definitions to system roles

NOTE: This function is only available if the System Roles Module is installed.

Use this task to add an account definition to system roles.

NOTE: Account definitions with the Only use in IT Shop option set can only be assigned to system roles that also have this option set.

To add account definitions to a system role

  1. In the Manager, select the Microsoft Entra ID > Basic configuration data > Account definitions > Account definitions category.

  2. Select an account definition in the result list.

  3. Select the Assign system roles task.

  4. In the Add assignments pane, assign system roles.

    TIP: In the Remove assignments pane, you can remove the system role assignment.

    To remove an assignment

    • Select the system role and double-click .

  5. Save the changes.
Related topics

Adding account definitions in the IT Shop

An account definition can be requested by shop customers when it is assigned to an IT Shop shelf. To ensure it can be requested, further prerequisites need to be guaranteed.

  • The account definition must be labeled with the IT Shop option.

  • The account definition must be assigned to a service item.

    TIP: In the Web Portal, all products that can be requested are grouped together by service category. To make the account definition easier to find in the Web Portal, assign a service category to the service item.

  • If the account definition is only assigned to identities using IT Shop assignments, you must also set the Only for use in IT Shop option. Direct assignment to hierarchical roles may not be possible.

NOTE: IT Shop administrators can assign account definitions to IT Shop shelves if login is role-based. Target system administrators are not authorized to add account definitions in the IT Shop.

To add an account definition to the IT Shop (role-based login)

  1. In the Manager, select the Entitlements > Account definitions category.

  2. Select an account definition in the result list.

  3. Select the Add to IT Shop task.

  4. To assign the account definition to shelves, select the IT Shop shelves tab and, in the Add assignments section, select the shelves with a double-click.

  5. To assign the account definition to IT Shop templates, select the IT Shop templates tab and, in the Add assignments section, select the template with a double-click.

  6. Save the changes.

To add an account definition to the IT Shop (non role-based login)

  1. In the Manager, select the Microsoft Entra ID > Basic configuration data > Account definitions > Account definitions category.

  2. Select an account definition in the result list.

  3. Select the Add to IT Shop task.

  4. To assign the account definition to shelves, select the IT Shop shelves tab and, in the Add assignments section, select the shelves with a double-click.

  5. To assign the account definition to IT Shop templates, select the IT Shop templates tab and, in the Add assignments section, select the template with a double-click.

  6. Save the changes.

To remove an account definition from individual IT Shop shelves (role-based login)

  1. In the Manager, select the Entitlements > Account definitions category.

  2. Select an account definition in the result list.

  3. Select the Add to IT Shop task.

  4. To remove the account definition from the shelves, select the IT Shop shelves tab and, in the Remove assignments section, double-click the shelves.

  5. To remove the account definition from the IT Shop templates, select the IT Shop templates tab and, in the Remove assignments section, double-click the templates.

  6. Save the changes.

To remove an account definition from individual IT Shop shelves (non role-based login)

  1. In the Manager, select the Microsoft Entra ID > Basic configuration data > Account definitions > Account definitions category.

  2. Select an account definition in the result list.

  3. Select the Add to IT Shop task.

  4. To remove the account definition from the shelves, select the IT Shop shelves tab and, in the Remove assignments section, double-click the shelves.

  5. To remove the account definition from the IT Shop templates, select the IT Shop templates tab and, in the Remove assignments section, double-click the templates.

  6. Save the changes.

To remove an account definition from all IT Shop shelves (role-based login)

  1. In the Manager, select the Entitlements > Account definitions category.

  2. Select an account definition in the result list.

  3. Select the Remove from all shelves (IT Shop) task.

  4. Confirm the security prompt with Yes.
  5. Click OK.

    The account definition is removed from all shelves by the One Identity Manager Service. At the same time, any requests and assignment requests with this account definition are canceled.

To remove an account definition from all IT Shop shelves (non role-based login)

  1. In the Manager, select the Microsoft Entra ID > Basic configuration data > Account definitions > Account definitions category.

  2. Select an account definition in the result list.

  3. Select the Remove from all shelves (IT Shop) task.

  4. Confirm the security prompt with Yes.
  5. Click OK.

    The account definition is removed from all shelves by the One Identity Manager Service. At the same time, any requests and assignment requests with this account definition are canceled.

For more information about requesting company resources through the IT Shop, see the One Identity Manager IT Shop Administration Guide.

Related topics

Assigning account definitions to Microsoft Entra ID tenants

The following prerequisites must be fulfilled if you implement automatic assignment of user accounts and identities resulting in administered user accounts (Linked configured state):

  • The account definition is assigned to the target system.

  • The account definition has the default manage level.

User accounts are only linked to the identity (Linked state) if no account definition is given. This is the case on initial synchronization, for example.

To assign the account definition to a target system

  1. In the Manager, select the Microsoft Entra ID tenant in the Microsoft Entra ID > Tenants category.

  2. Select the Change main data task.

  3. From the Account definition (initial) drop-down, select the account definition for user accounts.

  4. Save the changes.

Detailed information about this topic
Related Documents

The document was helpful.

Seleziona valutazione

I easily found the information I needed.

Seleziona valutazione