The User & Permissions Group Editor provides a wizard for copying edit permissions and the user interface of an existing permissions group to a new permissions group.
To copy a permissions group
This starts a wizard for copying permissions groups.
A name suggestion is already entered in the field which is made up from the customer prefix and the original permissions group name. You can alter this name but the customer prefix has to remain.
Option | Description | ||
---|---|---|---|
Permissions | Set this option to copy table and column permissions of the selected permissions group to the new permissions group. | ||
Navigation | Select this option to copy menu items, forms and tasks of the selected permissions group to the new permissions group. | ||
System user |
Select this option if the system user should be copied to the new permissions group.
|
The copying process may take some time. Each copy step and any error messages are displayed in the dialog window.
You can then run the following tasks:
To create a permissions group
Add a new permissions group using the menu item Permissions groups | New.
You can then run the following tasks:
Property | Description | ||
---|---|---|---|
Permissions group | Name of the permissions group. Label your own permissions groups with the prefix 'CCC' | ||
Description | Detailed description of the permissions group’s purpose. | ||
Remarks | Spare text box for additional explanation. | ||
Preprocessor condition |
You can add a preprocessor condition to permissions groups. This means that the permissions group is only effective when the condition is met. | ||
Permissions group binary pattern | The permissions group binary pattern is used to calculate effective system user permissions. It is provided by the DBQueue Processor. | ||
Only use for role-based authentication |
This group includes permissions, form assignments, menu items and program functions for role-based authentication. The permissions group can be assigned to One Identity Manager application roles and is assigned to dynamically determined system users. A direct assignment to non-dynamic system user is not permitted.
|
To create a new system user
Property | Description |
---|---|
System user | Name of the system user for logging into the administration tools. |
Password and password confirmation | Password for logging into the administration tools as system user. |
Remarks | Spare text box for additional explanation. |
Read-only | Set this option if the system is member in all permissions group but can only have read access. This results in overwriting all other edit permissions that the system user obtains through permissions group memberships. |
Logins | Logins with which the system user can log in to One Identity Manager tools. Enter the login in the form: Domain\User. This information is required if the authentication module "Account-based system user" is used for logging into the One Identity Manager tools. |
Administrative user | Specifies whether the user is an administrator. Administrative system users are automatically added to all non role-based permissions groups. |
Service account |
Specifies whether this is a system user used by a service account. This system user is not allocated a permissions groups but has all access permissions, tasks and program functionality. |
External password management |
Specifies whether the system user's password is determined by an external password manager. The password cannot be changed in One Identity Manager. Determining the system user's password must be custom implemented. |
© 2023 One Identity LLC. ALL RIGHTS RESERVED. Feedback Terms of Use Privacy