Configuration parameter | Meaning |
---|---|
QER\CalculateRiskIndex | Preprocessor relevant configuration parameter controlling system components for calculating an employee's risk index. Changes to the parameter require recompiling the database.
If the parameter is set, values can be entered and calculated for the risk index. |
To edit SharePoint role master data
The following properties are displayed for SharePoint roles.
Property | Description |
---|---|
Display name | SharePoint role display name. |
Permission level | Unique identifier for the permission level on which the SharePoint role is based. |
Site | Unique identifier for the site that inherits its permissions from the SharePoint role. |
Risk index |
Value for evaluating the risk of assigning the SharePoint role to user accounts. Enter a value between 0 and 1. This property is only visible when the configuration parameter QER\CalculateRiskIndex is set. |
Description | Spare text box for additional explanation. |
Service item | Service item data for requesting the group through the IT Shop. |
IT Shop |
Specifies whether the SharePoint role can be requested through the IT Shop. This SharePoint role can be requested by staff through the Web Portal and granted through a defined approval procedure. The SharePoint role can still be assigned directly to employees and hierarchical roles. |
Only for use in IT Shop |
Specifies whether the SharePoint role can only be requested through the IT Shop. This SharePoint role can be requested by staff through the Web Portal and granted through a defined approval procedure. The SharePoint role may not assigned directly to hierarchical roles. |
|
NOTE: If the SharePoint role references a permission level with the Hidden option set, the options IT Shop and Only use in IT Shop cannot be set. You cannot assign these SharePoint roles to user accounts or groups. |
SharePoint roles can be assigned directly or indirectly to user accounts. In the case of indirect assignment, employees and SharePoint roles are arranged in hierarchical roles. The number of SharePoint roles assigned to an employee is calculated from the position in the hierarchy and the direction of inheritance. If you add an employee to hierarchical roles and the employee owns a user authenticated user account, the user account is added to the SharePoint role. Prerequisites for indirect assignment of employees to user accounts:
Furthermore, IT Shop roles can be assigned to employees through SharePoint requests. Add employees to a shop as customers so that SharePoint roles can be assigned through IT Shop requests. All SharePoint roles, which are assigned to this shop as products, can be requested by the customers. Requested SharePoint roles are assigned to the employees after approval is granted.
|
NOTE: SharePoint roles that reference permission levels with have the option Hidden set, cannot be assigned to business roles and organizations. These SharePoint roles can be neither directly nor indirectly assigned to user accounts or groups. |
Assign SharePoint roles to departments, cost centers and locations in order to assign user accounts to them through these organizations.
To assign a SharePoint role to departments, cost centers or locations (non role-based login)
Assign organizations in Add assignments.
- OR -
Remove the organizations from Remove assignments.
To assign SharePoint roles to departments, cost centers or locations (role-based login)
- OR -
Select the category Organizations | Cost centers.
- OR -
Select the category Organizations | Locations.
- OR -
Remove SharePoint roles in Remove assignments.
Installed Module: | Business Roles Module |
You assign SharePoint roles to business roles in order to assign them to user accounts over business roles.
To assign a SharePoint role to business roles (non role-based login)
- OR -
Remove business roles from Remove assignments.
To assign SharePoint roles to a business role (non role-based login)
- OR -
Remove SharePoint roles in Remove assignments.
© 2023 One Identity LLC. ALL RIGHTS RESERVED. Feedback Terms of Use Privacy