The Master data page for a governed resource contains the properties for the resource, including the ownership assigned to the resource. As a business owner, you can reject ownership of a governed resource using this page.
To reject the ownership of a resource
In the Reject Ownership dialog, enter a reason in the text box and click Submit.
An email request is immediately sent and not added to the shopping cart.
To view the resource ownership rejection request, navigate to Request | My Requests | Request History.
As a business owner, you can use the web portal to see what classification level is assigned to the resources you own. The classification level information is available on the following pages in the Governed Data view:
These pages contain the following details related to classification for the selected resource.
Property | Description | ||
---|---|---|---|
Classification Level |
The classification level assigned to the resource.
| ||
Description |
Descriptive text (read-only) associated with the selected classification level.
| ||
Justification |
Use this text box to enter a reason for assigning the current classification level.
|
To view classification level assigned to owned resources
Open the All my resources tab and select the resource.
Open one of the following pages to view the current classification level assignment:
|
NOTE: In addition to viewing the properties on the Classification page, you can assign a different classification level to the selected resource. |
To classify an owned resource (web portal)
From this page, you can assign a classification level to the selected resource:
Click Save. A "Your changes have been saved" message appears at the top of page.
The Access page for a governed resource displays all Active Directory groups and accounts that have at least one of the five access permissions to the resource:
|
Note: Access control entries on governed resources, as displayed in the web portal by a business owner, may not always appear as expected. For example, the access right "List Folder Contents" will show as "AllowRead" and "AnyAllow" in the web portal. This is because the List Folder Contents right enables the "allow" read permissions. |
In addition, if the assigned permissions are not correct, you can submit a request to remove an access permission or modify the access permissions for a resource. For more information, see Changing access permissions for a governed resource.
To view the groups and accounts with access permissions for a governed resource
Select the Show assigned permissions option.
The Active Directory accounts that are directly on the security descriptor for the resource appear. The access permissions assigned to each account or group is also displayed.
(Optional) Select the Include accounts of type "Alias" and "Wellknown" check box to include those accounts in the access permissions grid.
Changing access permissions for a governed resource
Viewing access permissions of authorized accounts and groups
The Access page for a governed resource displays all Active Directory groups and accounts that have at least one of the five access permissions to the resource. In addition, if the security settings on this resource are incorrect, you can submit a request to modify the access rights.
To change the access permissions for a resource
To request the removal of a specific permission, click on the associated check mark (for example, click the check mark in the AllowFullControl column).
The Security modification dialog appears. The reason is pre-populated, but can be edited if necessary. Click Submit.
The request is immediately sent and not added to the shopping cart.
To request a different type of security modification (for example to add an additional permission), click the Request modification button.
In the Security modification dialog, enter the type of modification to be made in the Reason text box and click Submit.
The request is immediately sent and not added to the shopping cart.
To view the change resource security request, navigate to Request | My Requests | Request History.
© 2023 One Identity LLC. ALL RIGHTS RESERVED. Feedback Terms of Use Privacy