As soon as an identity is assigned to an application role, the identity becomes a member of the application role.
As soon as an identity is assigned to an application role, the identity becomes a member of the application role.
You can display identities that are assigned application roles for which you are responsible.
To display identities that are assigned an application role
In the menu bar, click Responsibilities > My Responsibilities.
In the navigation, click Application roles.
On the Application Roles page, click the application role whose memberships you want to display.
In the Edit Application role pane, click the Memberships tab.
(Optional) To display all members who were originally assigned through a dynamic role but have been excluded, click Excluded members.
You can display how an application role assignment under your responsibility came about by displaying an assignment analysis for the corresponding membership.
To display the assignment analysis for a membership
In the menu bar, click Responsibilities > My Responsibilities.
In the navigation, click Application roles.
On the Application Roles page, click the application role whose memberships you want to display.
In the Edit Application role pane, click the Memberships tab.
On the Memberships tab, click Secondary memberships.
Click the membership to display its assignment analysis.
You can assign identities to application roles for which you are responsible.
The following assignment options are available:
Assignment by request
Automatic assignment through a dynamic role
Revoking exclusion of a member
To assign an identity to a application role using a request
In the menu bar, click Responsibilities > My Responsibilities.
In the navigation, click Application roles.
On the Application Roles page, click the application role to which you want to assign an identity.
In the Edit Application Role pane, click the Memberships tab.
On the Memberships tab, click Request memberships.
In the Request Memberships pane, next to the identity to which you want to assign the application role, select the check box.
Click Request memberships.
Close the Edit Application Role pane.
In the menu bar, click Requests > Shopping cart.
On the Shopping Cart page, click Submit.
Once the request has been granted approval, the identity is assigned to the application role.
To add members automatically through a dynamic role
In the menu bar, click Responsibilities > My Responsibilities.
In the navigation, click Application roles.
On the Application Roles page, click the application role for which you want to create a dynamic role.
In the Edit Application Role pane, click the Memberships tab.
On the Memberships tab, click Automatic memberships.
Click Create dynamic role.
Use conditions to specify which identities to add over the dynamic role. Perform the following actions to do this:
Click Add condition.
In the Property menu, select the relevant property.
In the Operator menu, select a logical operator.
In the final field, specify a comparison value.
(Optional) To add another condition, click Add another condition and repeat the steps.
(Optional) To change the way the conditions are linked, you can toggle between And and Or by clicking the link.
TIP: To remove a condition, click (Delete).
For more information about customizing filter conditions, see Custom filter conditions.
Click Save.
(Optional) In the Calculation schedule menu, select the schedule that specifies when memberships are calculated.
(Optional) To calculate memberships immediately after a relevant object is changed, select the Assignments recalculated immediately check box.
Click Save.
TIP: A membership that was created through a dynamic role is labeled as Assigned by dynamic role in the memberships list.
In the menu bar, click Responsibilities > My Responsibilities.
In the navigation, click Application roles.
On the Application Roles page, click the application role to which you want to re-add a member.
In the Edit Application Role pane, click the Memberships tab.
On the Memberships tab, click Excluded members.
Select the check box next to the identity you want to add again as a member.
Click Remove exclusion.
© 2024 One Identity LLC. ALL RIGHTS RESERVED. 利用規約 プライバシー Cookie Preference Center