SharePoint Online user accounts provide the information necessary for user authentication, such as, the authentication mode and login names. In addition, permissions of users in a site collection are specified in the user accounts.
Each SharePoint Online user account represents an object from an authentication system trusted by the SharePoint Online system. In SharePoint Online, the authentication system is Azure Active Directory. The Azure Active Directory target system must be administrated in One Identity Manager. so that the object used for authentication on the usSharePoint Onlineer account can be saved as the authentication object. This means the SharePoint Online user account permissions are mapped to employees managed in One Identity Manager. One Identity Manager makes it possible for you to obtain an overview of all an employee's SharePoint Online access permissions. SharePoint Online permissions can be attested and checked for compliance. Employees can request or obtain the SharePoint Online permissions they requires through their memberships in hierarchical roles or through the Web Portal when appropriately configured.
By default, the following objects can be assigned as authentication objects in One Identity Manager.
-
Azure Active Directory groups of Security group type (AADGroup table)
-
Azure Active Directory user accounts (AADUser table)
During synchronization, One Identity Manager tries to assign the matching authentication object using the login name.
A user account can be linked to an employee in One Identity Manager. You can also manage user accounts separately from employees.
NOTE:
Related topics
- Application cases for SharePoint Online user account
- Managing SharePoint Online user accounts and employees
- Account definitions for SharePoint Online user accounts
- Default project template for SharePoint Online
- Editing master data for SharePoint Online user accounts
- Deleting and restoring SharePoint Online user accounts
- Managing the assignments of SharePoint Online groups and roles