Azure Active Directory administrator roles can be assigned directly or indirectly to Azure Active Directory user accounts.
In the case of indirect assignment, employees and Azure Active Directory administrator roles are assigned to hierarchical roles, such as, departments, cost centers, locations, or business roles. The Azure Active Directory administrator roles assigned to an employee are calculated from the position in the hierarchy and the direction of inheritance. If you add an employee to roles and that employee owns an Azure Active Directory user account, the Azure Active Directory user account is added to the Azure Active Directory administrator roles.
You can also request Azure Active Directory administration roles in the Web Portal. To do this, add employees to a shop as customers. All Azure Active Directory administrator roles assigned as products to this shop, can be requested by the customers. Requested Azure Active Directory administrator roles are assigned to the employees after approval is granted.
Through system roles, Azure Active Directory administrator roles can be grouped together and assigned to employees and workdesks as a package. You can create system roles that contain only Azure Active Directory administrator roles. You can also group any number of company resources into a system role.
To react quickly to special requests, you can assign Azure Active Directory administrator roles directly to Azure Active Directory user accounts.
For detailed information see the following guides:
Topic |
Guide |
---|---|
Basic principles for assigning and inheriting company resources |
One Identity Manager Identity Management Base Module Administration Guide One Identity Manager Business Roles Administration Guide |
Assigning company resources through IT Shop requests |
One Identity Manager IT Shop Administration Guide |
System roles |
One Identity Manager System Roles Administration Guide |
Detailed information about this topic
- Prerequisites for indirect assignment of Azure Active Directory administration roles to Azure Active Directory user accounts
- Assigning Azure Active Directory administrator roles to departments, cost centers, and locations
- Assigning Azure Active Directory administrator roles to business roles
- Adding Azure Active Directory administrator roles to system roles
- Adding Azure Active Directory administrator roles in the IT Shop
- Assigning Azure Active Directory user accounts directly to Azure Active Directory administrator roles
- Assigning Azure Active Directory administrator roles directly to Azure Active Directory user accounts