The following steps can be used to automatically add system entitlements to the IT Shop. Synchronization ensures that the system entitlements are added to the IT Shop. If necessary, you can manually start synchronization with the Synchronization Editor. New system entitlements created in One Identity Manager also are added automatically to the IT Shop.
To add system entitlements automatically to the IT Shop
-
In the Designer, set the configuration parameter for automatically adding system entitlements to the IT Shop depending on existing modules.
Example: QER | ITShop | AutoPublish | ADSGroup and QER | ITShop | AutoPublish | ADSGroup | ExcludeList
-
For disabled Microsoft Entra ID service plans:
QER | ITShop | AutoPublish | AADDeniedServicePlan
QER | ITShop | AutoPublish | AADDeniedServicePlan | ExcludeList
-
For Microsoft Entra ID groups:
QER | ITShop | AutoPublish | AADGroup
QER | ITShop | AutoPublish | AADGroup | ExcludeList
-
For Microsoft Entra ID subscriptions:
QER | ITShop | AutoPublish | AADSubSku
QER | ITShop | AutoPublish | AADSubSku | ExcludeList
-
For Active Directory groups:
QER | ITShop | AutoPublish | ADSGroup
QER | ITShop | AutoPublish | ADSGroup | ExcludeList
QER | ITShop | AutoPublish | ADSGroup | AutoFillDisplayName
If Active Roles Self-Service Manager is used:
TargetSystem | ADS | ARS_SSM
-
For Exchange Online mail-enabled distribution groups:
QER | ITShop | AutoPublish | O3EDL
QER | ITShop | AutoPublish | O3EDL | ExcludeList
-
For Microsoft 365 groups:
QER | ITShop | AutoPublish | O3EUnifiedGroup
QER | ITShop | AutoPublish | O3EUnifiedGroup | ExcludeList
-
For Microsoft Teams teams:
QER | ITShop | AutoPublish | O3TTeam
QER | ITShop | AutoPublish | O3TTeam | ExcludeList
-
For PAM user groups:
QER | ITShop | AutoPublish | PAGUsrGroup
QER | ITShop | AutoPublish | PAGUsrGroup | ExcludeList
-
For SharePoint groups:
QER | ITShop | AutoPublish | SPSGroup
QER | ITShop | AutoPublish | SPSGroup | ExcludeList
-
For OneLogin roles:
QER | ITShop | AutoPublish | OLGRole
QER | ITShop | AutoPublish | OLGRole | ExcludeList
-
-
Compile the database.
The system entitlements are added automatically to the IT Shop from now on.
The following steps are run to add a system entitlement to the IT Shop.
-
A service item is determined for the system entitlement.
The service item is tested for each system entitlement and modified if necessary. The name of the service item corresponds to the name of the system entitlement.
-
The service item is modified if the system entitlement has a service item.
-
System entitlements without a service item are allocated a new service item.
-
-
The service item is assigned to one of the default service categories.
-
An application role for product owners is determined and the service item is assigned. For more information, see the administration manuals for the respective target system connection.
Product owners can approve requests for membership in these system entitlements.
-
The system entitlement is labeled with the IT Shop option and assigned to the corresponding IT Shop shelf in the Identity & Access Lifecycle shop.
Subsequently, the shop's customers can request memberships in system entitlement through the Web Portal.
NOTE: When a system entitlement is irrevocably deleted from the One Identity Manager database, the associated service item is also deleted.