Permission levels with a unique reference to a site are mapped in the One Identity Manager database as SharePoint Online roles. You can assign SharePoint Online roles through groups, or directly to user accounts. SharePoint Online users obtain their permissions for site objects in this way.
NOTE: SharePoint Online roles and role assignments are handled as dependent objects by synchronization. That means, SharePoint Online roles must also be synchronized in order to synchronize role assignments.
Related topics
To edit SharePoint Online role master data
-
In the Manager, select the SharePoint Online | Roles category.
-
Select the SharePoint Online role in the result list and run the Change master data task.
-
Edit the master data for the role.
- Save the changes.
NOTE: If the SharePoint Online role references a permission level for which the Hidden option is set, the options IT Shop and Only use in IT Shop cannot be set. You cannot assign these SharePoint Online roles to user accounts or groups.
Related topics
The following properties are displayed for SharePoint Online roles.
Table 32: General master data for a SharePoint Online role
Display name |
SharePoint Online role display name. |
Permission level |
Unique identifier for the permission level on which the SharePoint Online role is based. |
Site |
Unique identifier for the site that inherits its permissions from the SharePoint Online role. |
Service item |
Service item data for requesting the role through the IT Shop. |
Category |
Categories for role inheritance. User accounts can inherit roles selectively. To do this, roles, and user accounts are divided into categories. Select one or more categories from the menu. |
Description |
Text field for additional explanation. |
IT Shop |
Specifies whether the SharePoint Online role can be requested through the IT Shop. This SharePoint Online role can be requested by staff through the Web Portal and granted through a defined approval procedure. The SharePoint Online role can still be assigned directly to employees and hierarchical roles. |
Only for use in IT Shop |
Specifies whether the SharePoint Online role can only be requested through the IT Shop. This SharePoint Online role can be requested by staff through the Web Portal and granted through a defined approval procedure. The SharePoint Online role may not be assigned directly to hierarchical roles. |
NOTE: If the SharePoint Online role references a permission level for which the Hidden option is set, the options IT Shop and Only use in IT Shop cannot be set. You cannot assign these SharePoint Online roles to user accounts or groups.
Detailed information about this topic
After you have entered the master data, you can run the following tasks.