Chat now with support
Chat with Support

Identity Manager 8.0 - Administration Guide for Connecting to Azure Active Directory

Managing Azure Active Directory Environments Setting Up Synchronization with an Azure Active Directory Tenant Base Data for Managing Azure Active Directory Azure Active Directory Core Directories Azure Active Directory user accounts Azure Active Directory groups Azure Active Directory Administrator Roles Azure Active Directory Subscriptions and Service Plans
Azure Active Directory Subscriptions Disabled Azure Active Directory Service Plan
Reports about Azure Active Directory Objects Appendix: Configuration Parameters for Managing Azure Active Directory Appendix: Default Project Template for Azure Active Directory

Assigning Additional Properties to an Azure Active Directory Subscription

Assigning Additional Properties to an Azure Active Directory Subscription

Extended properties are meta objects that cannot be mapped directly in the One Identity Manager, for example, operating codes, cost codes or cost accounting areas.

To specify extended properties for a subscription

  1. Select the category Azure Active Directory | Subscriptions.
  2. Select a subscription in the result list.
  3. Select Assign extended properties in the task view.
  4. Assign extended properties in Add assignments.

    The view- OR -

    Remove extended properties from Remove assignments.

  5. Save the changes.

For more detailed information about using extended properties, see the One Identity Manager Identity Management Base Module Administration Guide.

Disabled Azure Active Directory Service Plan

Disabled Azure Active Directory Service Plan

So called "disabled service plans" are mapped in the One Identity Manager to prevent users from using single service plans. Disabled service plans are created automatically after synchronizing the subscription in the One Identity Manager. Disabled service plans are requested through the IT Shop or assigned to users through departments, cost centers, locations, business roles or system roles.

Editing Master Data of Disabled Azure Active Directory Service Plans

Editing Master Data of Disabled Azure Active Directory Service Plans

To edit disabled service plan master data

  1. Select the category Azure Active Directory | Disabled service plans.
  2. Select the service plan in the result list.
  3. Select Change master data in the task view.
  4. Edit the service plan’s master data.
  5. Save the changes.
Table 46: Disabled Service Plan Master Data

Property

Description

Subscription Name of the subscription.
Service plan Name of the service plan.

IT Shop

Specifies whether the service plan can be requested through the IT Shop. The disabled service plan can be requested by your staff though the Web Portal and granted through a defined approval process. The disabled service plan can still be assigned directly to hierarchical roles.

Only for use in IT Shop

Specifies whether the disabled service plan can only be requested through the IT Shop. The disabled service plan can be requested by your staff though the Web Portal and granted through a defined approval process. The disabled service plan may not be assigned directly to hierarchical roles.

Service item

Service item data for requesting the disabled service plan through the IT Shop.

Category

Categories for disabled service plan inheritance. User accounts can selectively inherit disabled service plans. To do this, disabled service plans and user accounts are divided into categories. Use this menu to allocate one or more categories to the disabled service plan.
Related Topics

Assigning Disabled Azure Active Directory Service Plans to Azure Active Directory User Accounts

Assigning Disabled Azure Active Directory Service Plans to Azure Active Directory User Accounts

You can assign disabled service plans directly or indirectly to a user account. In the case of indirect assignment, employees and disabled service plans are assigned to hierarchical roles, such as, departments, cost centers, locations or business roles. The disabled service plans assigned to an employee are calculated from the position in the hierarchy and the direction of inheritance.

If the employee has a user account in Azure Active Directory, disabled service plans belonging to roles are inherited by this user account.

Prerequisites for indirect assignment of employees to user accounts:

  • Assignment of employees and disabled service plans is permitted for role classes (department, cost center, location or business role).
  • The user accounts are marked with the option Groups can be inherited.

Furthermore, disabled service plans can be assigned to employees through IT Shop requests. Add employees to a shop as customers so that disabled service plans can be assigned through IT Shop requests. All disabled service plans are assigned to this shop can be requested by the customers. Requested disabled service plans are assigned to the employees after approval is granted.

Detailed information about this topic
Related Documents