You can also apply the behavior described under Azure Active Directory Group Inheritance Based on Categories for disabled service plans.
To use inheritance through categories
Extended properties are meta objects that cannot be mapped directly in the One Identity Manager, for example, operating codes, cost codes or cost accounting areas.
To specify extended properties for a disabled service plan
Assign extended properties in Add assignments.
The view- OR -
Remove extended properties from Remove assignments.
For more detailed information about using extended properties, see the One Identity Manager Identity Management Base Module Administration Guide.
One Identity Manager makes various reports available containing information about the selected base object and its relations to other One Identity Manager database objects. The following reports are available for Azure Active Directory.
|
NOTE: Other sections may be available depending on the which modules are installed. |
Report |
Description |
---|---|
Overview of all Assignments |
This report finds all roles containing employees with at least one user account in the selected tenant. |
Show orphaned user accounts |
This report shows all user accounts in the tenant, which are not assigned to an employee. The report contains group memberships and risk assessment. |
Show employees with multiple user accounts |
This report shows all employees with more than one user account in the tenant. The report is a risk assessment. |
Show unused user accounts |
This report shows all the tenant's user accounts that have not been used in the last few months. The report contains group memberships and risk assessment. |
Show entitlement drifts |
This report shows all the groups in the tenant, which are the result of manual operations in the target system rather than provisioned through One Identity Manager. |
Show user accounts with an above average number of system entitlements |
This report contains all user accounts in the tenant with an above average number of group memberships. |
Azure Active Directory user account and group administration |
This report contains a summary of user account and group distribution in all tenants. You can find this report in the category My One Identity Manager. |
Data quality summary for Azure Active Directory user accounts |
This report contains different evaluations of user account data quality in all tenants. You can find this report in the category My One Identity Manager. |
The report "Overview of all Assignments" is displayed for certain objects, for example, permissions, compliance rules or roles. The report finds all the roles, for example, departments, cost centers, locations, business roles and IT Shop structures in which there are employee who own the selected base object. In this case, direct as well as indirect base object assignments are included.
To display detailed information about assignments
All the roles of the selected role class are shown. The color coding of elements identifies the role in which there are employees with the selected base object. The meaning of the report control elements is explained in a separate legend. In the report's toolbar, click to open the legend.
Figure 3: Toolbar for Report "Overview of all assignments"
Icon | Meaning |
---|---|
Show the legend with the meaning of the report control elements | |
Saves the current report view as a graphic. | |
Selects the role class used to generate the report. | |
|
Displays all roles or only the affected roles. |
© 2021 One Identity LLC. ALL RIGHTS RESERVED. Feedback Terms of Use Privacy