Probable cause
You may receive one of the following errors: “Not Authorized to Use this Database” or "Access was denied while attempting to perform the requested operation" if you are logged in to the machine with an Active Directory account that does not have an associated employee and appropriate roles to view and manage hosts. This account is used to contact the Data Governance server.
NOTE: Both the System user (account logged on to the machine) and the Manager user (account running the Manager) must have an associated One Identity Manager Employee and must be assigned the appropriate Data Governance application roles.
Resolution
To associate an account with an employee
- In the navigation view, select Active Directory (ADS button at bottom of navigation view).
- Select User accounts, and select the account that you are currently logged in to the machine as.
- In the Tasks view, select Change master data.
-
On the General tab, select an employee to associate with the account.
Note: Typically an Active Directory synchronization creates an employee for every Active Directory account and this association is already done.
The following application roles are specifically for Data Governance Edition. They are used with One Identity Manager application roles.
-
Data Governance | Access Managers
Members of this role can access all information related to Data Governance Edition, and can query information from Data Governance agents. Also, they can modify the security of objects contained on managed hosts.
-
Data Governance | Administrators
Members of this role can perform all administrative tasks necessary for the management of Data Governance Edition. This includes deploying and configuring managed hosts, managing data access, editing security, and placing data under governance.
-
Data Governance | Business Owner
Members of this role can view information on resources they own.
-
Data Governance | Direct Owners
This role is held by accounts and roles marked as the owners of resources within Data Governance Edition.
Note: This role cannot be assigned manually; it is assigned programmatically.
-
Data Governance | Managed Resources
A default container used for roles automatically generated by Data Governance Edition managed resources. For more information on managed resources, see the One Identity Manager Data Governance Edition IT Shop Resource Access Requests User Guide.
-
Data Governance | Operators
Members of this role have read-only access to the Managed hosts view and Agents view in the Manager.
-
Identity & Access Governance | Compliance & Security Officer
Members of this role have a view into all security-related information collected by Data Governance Edition. They are responsible for ensuring security-related compliance regulations are being followed correctly.
To assign application roles
- In the navigation view, select Employees | Employees.
- In the Employees result list, double-click the required employee.
- In the Task view, select Assign One Identity Manager application roles.
- Apply the required application role, and save your changes. For example:
- Expand Data Governance in the Add assignments window to view the application roles available.
- Double-click Administrators to assign the Data Governance | Administrators role to the selected user account.
- Click the Save toolbar button.
- Restart the Data Governance service to renew the authentication cache. The cache is renewed automatically if you are not using the Manager for 5 minutes.