There are particular cases where you may not want to have inheritance over several hierarchical levels. That is why it is possible to discontinue inheritance within a hierarchy. The point at which the inheritance should be discontinued within a hierarchy is specified by the option Block inheritance. The effects of this depend on the chosen direction of inheritance.
If the option Block inheritance is set for the department "Sales" in the top-down example, it results in sales employees being assigned address administration and employees in the retail department, address administration and internet software, but neither is assigned mail or text editing applications. Applications in the department "Overall organization" are, however, not assigned to retail and dealers.
Figure 3: Discontinuing Inheritance Top-Down
An employee from the project group "Programming" receives applications from the project group as well as those from the projects groups underneath. in this case, the development environment, assembler tool and the prototyping tool. If the project group "Programming" has labeled with the option Block inheritance, it no longer passes down inheritance. As a result, only the CASE tool is assigned to employees in the project group "Project lead" along with the application project management. Applications from the projects groups "Programming", "System programming" and "Interface design" are not distributed to the project lead.
Figure 4: Discontinuing Inheritance Bottom-Up
You can assign company resources to employees, devices and workdesks in the One Identity Manager. You can use different assignments types to assign company resources.
Assignments types are:
Direct assignment of company resources results from the assignment of a company resource to an employee, device or a workdesk, for example. Direct assignment of company resources makes it easier to react to special requirements.
Figure 5: Schema of a direct assignment based on the example of an employee
In the case of indirect assignment of company resources, employees, devices and workdesks are arranged in departments, cost centers, locations, business roles or application roles. The total of assigned company resources for an employee, device or workdesk is calculated from the position within the hierarchies, the direction of inheritance (top-down or bottom-up) and the company resources assigned to these roles. In the Indirect assignment methods a difference between primary and secondary assignment is taken into account.
Figure 6: Schema of an indirect assignment based on the employee example
© 2023 One Identity LLC. ALL RIGHTS RESERVED. Feedback Terms of Use Privacy