To delete the EMPTemplate
- Remove the Epic EMP template from the EMPTemplate.csv file.
- In Synchronization Editor, run the Synchronization project.
The Epic EMP template is marked as outstanding in One Identity Manager.
-
Remove the Epic EMP template assignment from the Epic EMP user in One Identity Manager.
-
Delete the Epic EMP template from the outstanding object
The Epic EMP template is deleted from the One Identity Manager database and all the associated Epic EMP template to the Epic EMP user.
Epic EMP subtemplate determines the access rights that a user has on an Epic System. The list of Epic EMP subtemplates are exported from the target system to the file SubTemplate.csv.
Epic EMP subtemplate is loaded into One Identity Manager by synchronization. You can assign and remove Epic EMP subtemplate from an user in One Identity Manager. However, you cannot edit the Epic EMP subtemplate in One Identity Manager.
To add Epic EMP subtemplate to Epic EMP users, you can assign the Epic EMP subtemplate directly to the Epic EMP users. This can be assignments of Epic EMP subtemplate to departments, cost centers, location, business roles, or to the IT Shop.
Epic EMP subtemplate assigned to an Epic EMP user must have a priority (also called index). Epic EMP subtemplates with lower priority take precedence over higher priority. Epic EMP users can be assigned a maximum of seven Epic EMP subtemplates with priority ranging from 1-7.
In case of conflicting priority in the new assignment, One Identity Manager resolves the conflict by maintaining the priority of the newly created Epic EMP subtemplate while incrementing the priority of all existing Epic EMP subtemplate by 1 starting from the conflicting priority.
To add Epic EMP subtemplate to users, you can assign the Epic EMP subtemplate directly to the users. This can be assignments of Epic EMP subtemplate to departments, cost centers, location, business roles, or to the IT Shop.
Epic EMP subtemplate assigned to an Epic EMP user must have a priority (also called index). Epic EMP subtemplates with lower priority take precedence over higher priority. Epic EMP users can be assigned a maximum of seven Epic EMP subtemplates with priority ranging from 1-7.
In case of conflicting priority in the new assignment, One Identity Manager resolves the conflict by maintaining the priority of the newly created Epic EMP subtemplate while incrementing the priority of all existing Epic EMP subtemplate by 1 starting from the conflicting priority.
The default value of IndexPriority can be set in One Identity Designer |Edit Configuration parameters.
Table 29: Default values of IndexPriority
Default value |
Description |
SubTemplateDefaultPriority |
This default value is used for indirect assignment |
SubTemplateMatrixPriority |
This default value is used for SecurityMatrix Epic EMP subtemplate assignment |
Edit default values of IndexPriority
To edit the default values of IndexPriority
- In Designer, navigate to Edit Navigation Parameter.
- Expand Target Systems and navigate to EPC.
- Update the Default Values.
Format of the CSV file SubTemplate.csv
The CSV file SubTemplate.csv has a specific format with the following columns TemplateID and TemplateName.
The columns in the SubTemplate.csv file are
Table 30: Columns in the SubTemplate.csv file
Column name |
Description |
TemplateID |
Epic EMP subtemplate’s External ID
IMPORTANT:
Only External ID should be used. |
TemplateName |
Describes the Epic EMP subtemplate name |
NOTE:
- If the TemplateName or TemplateID field has comma (,), it must be properly escaped with double quotes.
- Sample Epic EMP SubTemplate report can be found in the EPC module’s Miscellaneous folder.
Epic EMP subtemplate is loaded into One Identity Manager by synchronization.
Only TemplateName can updated in the csv file. If TemplateID is updated it will be considered as new Template in the One Identity Manager.
To edit the Epic EMP subtemplate
- In SubTemplate.csv, modify the rows.
- In the Synchronization Editor, run the Synchronization project.
- Epic EMP subtemplate data will be synchronized based on the operation performed on the SubTemplate.csv.
Epic EMP subtemplate can be assigned directly or indirectly to Epic EMP user. For indirect assignment, identities are assigned to hierarchical roles, such as, departments, cost cent res, locations, or business roles.
Prerequisite for the indirect assignment of Epic EMP subtemplate to the identities.
- Assignment of Epic EMP subtemplate is permitted for role classes (departments, cost centers, locations, or business roles).
- Epic User accounts are marked with the Epic EMP subtemplate can be inherited option.
NOTE: Epic EMP subtemplate can also be assigned to Epic user through IT shop.