One Identity Manager uses different assignment types to assign company resources.
In the case of indirect assignment of company resources, employees, devices and workdesks are arranged in departments, cost centers, locations, business roles or application roles. The total of assigned company resources for an employee, device or workdesk is calculated from the position within the hierarchies, the direction of inheritance (top-down or bottom-up) and the company resources assigned to these roles. In the Indirect assignment methods a difference between primary and secondary assignment is taken into account.
Direct assignment of company resources results from the assignment of a company resource to an employee, device or a workdesk, for example. Direct assignment of company resources makes it easier to react to special requirements.
Assignment through dynamic roles is a special case of indirect assignment. Dynamic roles are used to specify role memberships dynamically. Employees, devices and workdesks are not permanently assigned to a role, just when they fulfill certain conditions. A check is performed regularly to assess which employees, devices or workdesks fulfill these conditions. The means the role memberships change dynamically. For example, company resources can be assigned dynamically to all employees
The following table shows the possible company resources assignments to devices.
|Note: Company resources are defined in the One Identity Manager modules and are not available until the modules are installed.|
|Company resources||Direct assignment permitted||Indirect assignment permitted||Comment|
Active Directory groups
All Active Directory computers, which reference this device are added to Active Directory groups.
All LDAP computers, which reference this device are added to LDAP groups.
|NOTE: Devices also obtain company resources from their workdesks.|
Assign devices to departments, cost centers and locations so that they obtain company resources through these organizations. To assign company resources to departments, cost centers and locations, use the appropriate organization tasks.
To assign a device to departments, cost centers and locations (secondary assignment; default method)
Assign organizations in Add assignments.
- OR -
Remove the organizations from Remove assignments.
To assign a device to departments, cost centers and locations (primary assignment)
|Installed Modules:||Business Roles Module|
Assign devices to business roles such that the devices obtain company resources through these business roles. To assign company resources to business roles user the corresponding business role tasks.
To assign a device to business roles (secondary assignment; default method)
Assign business roles in Add assignments.
- OR -
Remove business roles from Remove assignments.
To assign a device to business roles (primary assignment)
After you have entered the master data, you can apply different tasks to it. The task view contains different forms with which you can run the following tasks.