Cloud groups and system entitlements can be assigned to employees directly or indirectly.
In the case of indirect assignment, employees as well as groups and entitlements are organized in hierarchical roles. The number of groups and system entitlements assigned to an employee is calculated from the position in the hierarchy and the direction of inheritance. If you add an employee to hierarchical roles and that employee owns a cloud user account, this user account is added to the cloud groups and system entitlements.
Cloud groups and system entitlements can also be requested in the Web Portal. To do this, add employees to a shop as customers. All cloud groups and system entitlements assigned to this shop as products can be requested by the customers. After approval is granted, requested cloud groups and system entitlements are assigned to the employees.
Through system roles, cloud groups and system entitlements can be grouped together and assigned to employees as a package. You can create system roles that contain only cloud groups or system entitlements. You can also group any number of company resources into a system role.
To react quickly to special requests, you can assign cloud groups and system entitlements directly to user accounts.
Topic |
Guide |
---|---|
Basic principles for assigning and inheriting company resources |
One Identity Manager Identity Management Base Module Administration Guide One Identity Manager Business Roles Administration Guide |
Assigning company resources through IT Shop requests |
One Identity Manager IT Shop Administration Guide |
System roles |
One Identity Manager System Roles Administration Guide |
Detailed information about this topic
- Prerequisites for indirect assignment of cloud groups
- Assigning cloud groups to departments, cost centers, and locations
- Assigning cloud system entitlements to departments, cost centers, and locations
- Assigning cloud groups to business roles
- Assigning cloud system entitlements to business roles
- Adding cloud groups to system roles
- Adding cloud system entitlements to system roles
- Adding cloud groups to the IT Shop
- Adding cloud system entitlements to the IT Shop
- Assigning cloud user accounts directly to cloud groups
- Assigning cloud user account directly to cloud system entitlements
- Assigning cloud groups directly to cloud user accounts
- Assigning cloud system entitlements directly to cloud user accounts