The following users are used for the administration of departments, cost centers and locations.
User | Task | ||
---|---|---|---|
Administrators for organizations
|
Administrators must be assigned to the application role Identity Management | Organizations | Administrators. Users with this application role:
| ||
One Identity Manager administrators
|
| ||
Approvers for organizations
|
Attestors must be assigned to the application role Identity Management | Organizations | Attestors or a child application role. Users with this application role:
| ||
Approvers for organizations
|
Approvers must be assigned to the application role Identity Management | Organizations | Approvers or a child application role. Users with this application role:
| ||
Approvers (IT) for organizations
|
IT role approvers must be assigned to the application role Identity Management | Organizations | Role approvers (IT) or a child application role. Users with this application role:
|
The following basic information is relevant for building up hierarchical roles in One Identity Manager.
Use configuration parameters to configure the behavior of the system's basic settings. One Identity Manager provides default settings for different configuration parameters. Check the configuration parameters and modify them as necessary to suit your requirements.
Configuration parameters are defined in the One Identity Manager modules. Each One Identity Manager module can also install configuration parameters. You can find an overview of all configuration parameters in the category Base data | General | Configuration parameters in the Designer.
Role classes form the basis of mapping from hierarchical roles in the One Identity Manager. Role classes are used to group similar roles together.
Create role types in order to classify roles. Roles types can be used to map roles in the user interface, for example.
To analyze rule checks for different areas of your company in the context of identity audit, you can set up functional areas. Functional areas can be assigned to roles. You can enter criteria that provide information about risks from rule violations for functional areas and roles.
Role classes form the basis of mapping from hierarchical roles in the One Identity Manager. Role classes are used to group similar roles together. Following role classes are provided by default for mapping organizations in One Identity Manager.
|
NOTE: You cannot delete the default role classes. However, you can edit their master data. |
To edit role classes
- OR -
Click in the result list toolbar.
Enter the following master data for a role class.
Property |
Description | ||
---|---|---|---|
Role classes |
Role class description The role class is displayed under this name in the navigation view. | ||
Attestors |
Applications role whose members are authorized to approve attestation instances for all roles in this role class. To create a new application role, click
| ||
Description |
Spare text box for additional explanation. | ||
Inherited top down |
Direction of inheritance top-down. Top-down inheritance is defined for departments, cost centers, locations and application roles. | ||
Inherited bottom-up |
Direction of inheritance bottom-up | ||
Assignment allowed |
Specifies whether assignments of respective object types to roles of this role class are allowed in general. | ||
Assignment not allowed |
Specifies whether respective object types can be assigned directly to roles of this role class. |
Create role types in order to classify roles. Roles types can be used to map roles in the user interface, for example.
To edit role types
- OR -
Click in the result list toolbar.
Enter the following master data for a role type:
Property | Description |
---|---|
Role type | Role type description |
Description | Spare text box for additional explanation. |
© 2023 One Identity LLC. ALL RIGHTS RESERVED. Feedback Terms of Use Privacy