The report "Overview of all Assignments" is displayed for certain objects, for example, permissions, compliance rules or roles. The report finds all the roles, for example, departments, cost centers, locations, business roles and IT Shop structures in which there are employee who own the selected base object. In this case, direct as well as indirect base object assignments are included.
To display detailed information about assignments
All the roles of the selected role class are shown. The color coding of elements identifies the role in which there are employees with the selected base object. The meaning of the report control elements is explained in a separate legend. In the report's toolbar, click to open the legend.
Figure 13: Toolbar for Report "Overview of all assignments"
Icon | Meaning |
---|---|
Show the legend with the meaning of the report control elements | |
Saves the current report view as a graphic. | |
Selects the role class used to generate the report. | |
|
Displays all roles or only the affected roles. |
Configuration parameter | Active Meaning |
---|---|
QER\Person\MasterIdentity |
Preprocessor relevant configuration parameter for controlling the component parts for administrating several identities of one employee. Changes to the parameter require recompiling the database.
If this parameter is set, several logical employees can be handled in the database for one physical employee (for example, an employee has different identities and account characteristics at different branches). |
QER\Person\MasterIdentity\UseMasterForAuthentication |
This configuration parameter specifies whether the main identity should be used to log in to One Identity Manager tools through an employee linked authentication module.
If this parameter is set, the main identity is used for employee linked authentication. If the parameter is not set, the subidentity for employee-linked authentication is used. |
It might be necessary for employees to have different identities for their work under certain circumstances – for example, identities that result from contracts at different branches. These identities can be differentiated through the membership of a department, cost center or through access permissions. External employees at different locations can also be used and represented with different identities in the system. You can define a main identity and a subidentity for an employee in the One Identity Manager to represent each of the identities and to group them at a central location.
|
TIP: If an employee with multiple identities is being edited despite only one identity being currently known to the One Identity Manager, you should create a main identity for that employee.You should assign the previously know identity as a subidentity and create new subidentities for the other identities. In this way, it is possible to test the employee’s permitted permissions per subidentity or per main identity including all subidentities in the bounds of an identity audit. |
Installed Modules: | Attestation Module |
User can log in through the Web Portal who only have temporary or limited access to the One Identity Manager. This functionality can be used, for example, if external employees, such as contract workers, should be provided with temporary access to the One Identity Manager. These employee can log in to the Web Portal as new workers. New employee objects are added for them in the One Identity Manager database.
If you make use of this functionality, take note of the following:
Certification status | new |
Certified | enabled |
No inheritance | enabled |
Installed Modules: | Attestation Module |
Employee's certification status is set by default through certification and recertification procedures. You can manually change an employee's certification status if it is necessary to do so outside the regular recertification schedule.
Prerequisite
To change an employee's certification status manually
- OR -
To change certification status of a inactive employee, select the category Employees | Inactive.
The new certification status for the employee is displayed on the form.
|
NOTE: The option Permanently disabled is updated with respect to the certification status. If an employee's certification status is set to "rejected" through attestation or manually, the employee is immediately permanently disabled. If the employee's certification status is changed to "certified", the employee is enabled again. |
© 2023 One Identity LLC. ALL RIGHTS RESERVED. Feedback Terms of Use Privacy