Managing system entitlements
You can use the Web Portal to manage system entitlements.
System entitlements map the objects that control access to target system resources in the target systems. A user account obtains the required permissions for accessing target system resources through its memberships in system entitlements.
Detailed information about this topic
Displaying system entitlements
You can see any of the system entitlements and their details.
To display system entitlements
-
In the menu bar click Data administration > Data Explorer.
-
In the Data Explorer navigation click System entitlements.
This opens the System Entitlements page and displays all the system entitlements.
-
(Optional) To display details of a system entitlement, click it in the list.
Making system entitlements requestable
To be able to request a system entitlements in the Web Portal, the system entitlement must fulfill the following prerequisites:
To make a system entitlement requestable
-
In the menu bar click Data administration > Data Explorer.
-
In the Data Explorer navigation, click System entitlements.
-
(Optional) To display only those system entitlements only that are not marked as requestable, perform the following actions:
-
Click (Filter).
-
In the filter context menu, select the Not requestable check box.
-
In the list, select the check box in front of the system entitlement that you want to make requestable.
-
Under the list, set the switch to Make selected items requestable and click Update.
TIP: If you do not want the system entitlement to be requested in the Web Portal anymore, set the switch to Make selected items not requestable.
Related topics
Displaying and editing system entitlements main data
You can see and edit system entitlements' main data.
To display and edit a system entitlement's main data
-
In the menu bar click Data administration > Data Explorer.
-
In the Data Explorer navigation, click System entitlements.
-
On the System Entitlements page, click the system entitlement whose main data you want to display.
-
In the Edit System Entitlement pane, make your changes in the relevant fields.
Table 26: System entitlement main data
Name |
Enter a full, descriptive name for the system entitlement. |
Canonical name |
Shows the automatically generated canonical name of the system entitlement. |
Distinguished name |
Shows the automatically generated distinguished name of the system entitlement. |
Display name |
Enter a name for displaying the system entitlement in the One Identity Manager tools. |
Notes domain |
Shows the Notes domain name. |
Description |
Enter a description for the system entitlement. |
Category |
Select the category for system entitlement inheritance. User accounts can inherit system entitlements selectively. To do this, system entitlements and user accounts are divided into categories. |
IT shop |
Enable this check box to allow the system entitlement to be requested through the IT Shop. This system entitlement can be requested by your identities through the Web Portal and granted through a defined approval process. The system entitlement can still be assigned directly to identities and hierarchical roles. For detailed information about IT Shop, see the One Identity Manager IT Shop Administration Guide. |
Only use in IT Shop |
Enable the check box to allow the system entitlement to be requested through the IT Shop if required. This system entitlement can be requested by your identities through the Web Portal and granted using a defined approval process. The system entitlement may not be assigned directly to hierarchical roles. |
-
Click Save.