Identities (workdesks or devices) and Active Directory groups are grouped into hierarchical roles in the case of indirect assignment. When assigning Active Directory groups indirectly, check the following settings and modify them if necessary.
Prerequisites for indirect assignment of Active Directory groups to identities' Active Directory user accounts and Active Directory contacts
-
Assignment of identities and Active Directory groups is permitted for role classes (departments, cost centers, locations, or business roles).
-
The Active Directory user accounts and Active Directory contacts are linked to identities.
-
Active Directory user accounts and Active Directory contacts are labeled with the Groups can be inherited option.
Prerequisites for indirect assignment of Active Directory groups to Active Directory computers
-
Assignment of devices and Active Directory groups is permitted for role classes (departments, cost centers, locations, or business roles).
-
The Active Directory computer is connected to a device.
-
The device is labeled as a PC or server.
-
The TargetSystem | ADS | HardwareInGroupFromOrg configuration parameter is set.
Prerequisites for indirect assignment to Active Directory groups to Active Directory computers through workdesks
-
Assignment of workdesks and groups is permitted for the role class (department, cost center, location, or business role).
-
The computer is connected to a device labeled as PC or server. This device owns a workdesk.
To configure assignments to roles of a role class
-
In the Manager, select role classes in the Organizations > Basic configuration data > Role classes category.
- OR -
In the Manager, select role classes in the Business roles > Basic configuration data > Role classes category.
-
Select the Configure role assignments task and configure the permitted assignments.
-
To generally allow an assignment, enable the Assignments allowed column.
-
To allow direct assignment, enable the Direct assignments permitted column.
-
- Save the changes.
NOTE: There are other configuration settings that play a role when company resources are inherited through departments, cost centers, locations, and business roles. For example, role inheritance might be blocked or inheritance of identities