Enter the following data for a dynamic role.
Property | Description | ||||
---|---|---|---|---|---|
Role |
Role (department, cost center, location, business role, IT Shop node, application node) referenced by the dynamic role. This data is preset with the selected role. | ||||
Object class |
Object class that the dynamic role applies to. Select either "Employee", "Hardware" or "Workdesk".
| ||||
Dynamic role |
Name of the dynamic role. | ||||
Calculation schedule |
Schedule, which triggers cyclical recalculation of the role membership. The task "default schedule dynamic role check" is already defined in the standard version of the One Identity Manager. All dynamic role memberships are checked using this schedule and recalculation requests are sent to the DBQueue Processor if necessary. Use the Designer to customize schedules or set up new ones to meet your requirements. | ||||
Description |
Spare text box for additional explanation. | ||||
Condition |
The condition defines which objects of the object class become members of the selected role. The condition is defined as a valid Where clause for a database query and has to relate to the selected object class. You can enter the condition directly as an SQL query or use the wizard for entering database queries. Alternatively, you can enter conditions for employee objects with the filter designer.
|
You should test which objects fulfill the given condition before you save a dynamic role.
|
NOTE: This task is only visible when the dynamic role condition is displayed as SQL query. |
To test the SQL condition
This displays the condition as SQL query.
All the objects found by the condition are displayed on the master data form in the Test result field.
Configuration parameter | Meaning |
---|---|
QER\Structures\DynamicGroupCheck |
This configuration parameter controls the generation of calculation tasks for dynamic roles. If the configuration parameter is not set, the subparameters do not apply. |
QER\Structures\DynamicGroupCheck\ |
If the parameter is set, a calculation task for modifications to employees or employee level objects is queued immediately in the DBQueue Processor. If the parameter is not set, the calculation tasks are queued the next time the schedule is planned to run. |
QER\Structures\DynamicGroupCheck\ |
If the parameter is set, a calculation task for modifications to employees or employee level objects is queued immediately in the DBQueue Processor. If the parameter is not set, the calculation tasks are queued the next time the schedule is run. |
QER\Structures\DynamicGroupCheck\ |
If the parameter is set, a calculation task for modifications to workdesks or workdesk level objects is queued immediately in the DBQueue Processor. If the parameter is not set, the calculation tasks are started the next time the schedule is planned to run. |
In order to calculate role memberships, the One Identity Manager tests every dynamic role to ensure that:
If one of the conditions is fulfilled, a request to add or delete memberships is sent to the DBQueue Processor. When the dynamic roles are tested, employee objects that are marked for deletion are:
Tasks for recalculating memberships are set up depending on the configuration parameter settings by:
The task "default schedule dynamic role check" is already defined in the standard version of the One Identity Manager. All dynamic role memberships are checked using this schedule and recalculation requests are sent to the DBQueue Processor if necessary. Checks are made at predefined intervals. Use the Designer to customize schedules or set up new ones to meet your requirements.
Memberships are immediately checked by the DBQueue Processor and changed is necessary when object properties are changed. To use this function, set the configuration parameters "QER\Structures\DynamicGroupCheck\CalculateImmediatelyPerson", "QER\Structures\DynamicGroupCheck\ CalculateImmediatelyHardware" and "QER\Structures\DynamicGroupCheck\ CalculateImmediatelyWorkdesk" in the Designer.
After you have entered the master data, you can apply different tasks to it. The task view contains different forms with which you can run the following tasks.
© 2023 One Identity LLC. ALL RIGHTS RESERVED. Feedback Terms of Use Privacy