Azure Active Directory groups can be assigned directly or indirectly to Azure Active Directory user accounts.
In the case of indirect assignment, employees and Azure Active Directory groups are assigned to hierarchical roles, such as departments, cost centers, locations, or business roles. The Azure Active Directory groups assigned to an employee are calculated from the position in the hierarchy and the direction of inheritance. If you add an employee to roles and that employee owns an Azure Active Directory user account, the Azure Active Directory user account is added to the Azure Active Directory group.
Furthermore, Azure Active Directory groups can be requested through the Web Portal. To do this, add employees to a shop as customers. All Azure Active Directory groups are assigned to this shop can be requested by the customers. Requested Azure Active Directory groups are assigned to the employees after approval is granted.
Through system roles, Azure Active Directory groups can be grouped together and assigned to employees and workdesks as a package. You can create system roles that contain only Azure Active Directory groups. You can also group any number of company resources into a system role.
To react quickly to special requests, you can assign Azure Active Directory groups directly to Azure Active Directory user accounts.
For detailed information see the following guides:
Topic |
Guide |
---|---|
Basic principles for assigning and inheriting company resources |
One Identity Manager Identity Management Base Module Administration Guide One Identity Manager Business Roles Administration Guide |
Assigning company resources through IT Shop requests |
One Identity Manager IT Shop Administration Guide |
System roles |
One Identity Manager System Roles Administration Guide |
Detailed information about this topic
- Prerequisites for indirect assignment of Azure Active Directory groups to Azure Active Directory user accounts
- Assigning Azure Active Directory groups to departments, cost centers and locations
- Assigning Azure Active Directory groups to business roles
- Adding Azure Active Directory groups to system roles
- Adding Azure Active Directory groups to the IT Shop
- Assigning Azure Active Directory user accounts directly to Azure Active Directory groups
- Assigning Azure Active Directory groups directly to Azure Active Directory user accounts