Chat now with support
Chat with Support

Identity Manager 8.1.4 - Business Roles Administration Guide

Managing business roles
One Identity Manager users for business roles Hierarchical role structure basic principles Basic principles for assigning company resources Basics of calculating inheritance Preparing business roles for company resource assignments Basic data for structuring business roles Editing business roles Assigning employees, devices, and workdesks to business roles Assigning business roles to company resources Analyzing role memberships and employee assignments Setting up IT operating data Additional tasks for managing business roles Reports about business roles
Role mining in One Identity Manager

Customizing the program settings

To change the program settings

  • In the menu, select the Database | Settings... item.
Table 20: Program settings
Setting Meaning

Automatically close analysis information window on completion

If this option is set and analyses are predefined, the information window is closed after analysis. If the option is not set, the information window is shown. Click the Finished button to close the window.

Show permissions weighting

Set this option to also display a weighting for the permissions.

Role naming template

Define a template for role names. This is used when to format new role names in predefined analysis methods. The template support following variables:

%sequence%

Sequential number

%object%

Name of first object in cluster

%property%

Name of first property in cluster

Running an analysis

To start analyzing with the Analyzer

Selecting analysis data using the wizard

Before you start the analysis, you collect your initial data. The Analyzer accesses all permissions information in its own database and creates a mapping table with employees and their permissions. The result can be suggestions for single roles from analyzing a single application but also cross-system roles from analyzing permissions in several systems.

To select initial data

  1. On the Analyzer’s start page, select the Select data with wizard menu item.
  2. Click Start.
  3. Specify an employee group to analyze. Select one of the following selection methods.
    • Structures

      Employees can be selected through the organization and business roles contained in One Identity Manager.

      1. Select the Structures selection method.
      2. Click Next.
      3. In the Structures list, select the organization or business role for analysis.

        The employees assigned to this structure are displayed in the Employees list. Use the Show directly/indirectly assigned employees buttons in the title bar to filter the employees.

        Table 22: Icons for filtering the employee list
        Icon Meaning
        Show indirectly assigned employees.
        Show directly assigned employees.
        Show employees from child nodes.
      4. Click Next.
    • Query wizard

      Define the condition used to find the employees in the database. The wizard helps you to formulate a condition (where clause) for database queries. The complete database query is composed internally. The database query references the "Person" table. For more information about using the wizard, see One Identity Manager User Guide for One Identity Manager Tools User Interface.

    • Menu

      The list displays all the employees in the One Identity Manager database. Use Shift + select or Ctrl + select to select several employees for analysis.

    • Load wizard template

      Load an existing configuration. Select the template file and click Open.

  4. Click Next.
  5. Select the target system whose user accounts and permissions will be included in the analysis. User Ctrl + select to multi-select target systems.
  6. Click Next.
  7. Specify the analysis methods. The following methods are available.
    Table 23: Analysis method
    Analysis method Description

    Simple cluster analysis/Complex cluster analysis

    Permissions are grouped into new business roles using cluster analysis methods and employees are assigned.

    The Analyzer supports automatic role mining by two different cluster analysis methods, which differ in terms of how they calculate the distances between individual clusters.

    Decision hierarchy

    Permissions are grouped into new business roles in a decision hierarchy and the employees are assigned. The number of group members is taken as the decision criteria.

    Structure assignment

    The permissions are assigned to an existing structure hierarchy. The use of existing structures, for example, organizational structure from ERP systems, is possible.

    Permissions analysis

    Employee permissions are analyzed with the help of permissions analysis. Business roles are freely defined and assignments of permissions and employees are evaluated manually based on the existing permissions.

  8. Click Next.
  9. (Optional) To reuse the configuration at a later time, set the Save configuration as template option. Select the directory path for saving the file using the file browser and click Save.
  10. Click Finish to start the analysis.

    This loads the data and starts the analysis. The results of the analysis are subsequently displayed. For more information, see Analysis evaluation.

  11. Create a new business role if required and assign the employees. Add the suggested changes to the One Identity Manager database. For more information, see Transferring changes.

Predefined analyses

NOTE: Analysis methods are made available when the Active Directory Module is present.

The following predefined analyses are provided:

  • Employee Active Directory permissions

    The permissions of all employees with Active Directory group memberships are analyzed.

  • Employee Active Directory permissions and departments

    The permissions of all employees with Active Directory group memberships are analyzed. Departments with Active Directory groups are also included in the analysis.

To start predefined analysis

  1. On the Analyzer's home page, select the Active Directory employee permissions or the Active Directory employee permissions and departments menu item.
  2. Click Start.

    This loads the analysis data and starts analysis immediately. This may take some time, depending on the amount of data.

    Analysis data is displayed depending on the program settings. Click Expand... to see detailed information. Click Finish to close the dialog. The results of the analysis are subsequently displayed. For more information, see Analysis evaluation.

Related Documents

The document was helpful.

Select Rating

I easily found the information I needed.

Select Rating