Chat now with support
Chat with Support

Identity Manager 8.1.5 - Administration Guide for Connecting to Azure Active Directory

Managing Azure Active Directory environments Setting up synchronization with an Azure Active Directory tenant Basic data for managing an Azure Active Directory environment Azure Active Directory core directories Azure Active Directory user accounts Azure Active Directory groups Azure Active Directory administrator roles Azure Active Directory subscriptions and service plans
Azure Active Directory subscriptions Disabled Azure Active Directory service plans
Reports about Azure Active Directory objects Configuration parameters for managing an Azure Active Directory environment Default project template for Azure Active Directory

Adding Azure Active Directory groups to the IT Shop

When you assign a group to an IT Shop shelf, it can be requested by the shop customers. To ensure it can be requested, further prerequisites need to be guaranteed:

  • The group is not a dynamic group.

  • The group must be labeled with the IT Shop option.

  • The group must be assigned a service item.

    TIP: In the Web Portal, all products that can be requested are grouped together by service category. To make the group easier to find in the Web Portal, assign a service category to the service item.

  • If you only want the group to be assigned to employees through IT Shop requests, the group must also be labeled with the Use only in IT Shop option. Direct assignment to hierarchical roles or user accounts is no longer permitted.

NOTE: With role-based login, the IT Shop administrators can assign groups to IT Shop shelves. Target system administrators are not authorized to add groups to IT Shop.

To add a group to the IT Shop.

  1. In the Manager, select Azure Active Directory | Groups category (non role-based login) category.

    - OR -

    In the Manager, select the Entitlements | Azure Active Directory groups (role-based login) category.

  2. In the result list, select the group.
  3. Select the Add to IT Shop task.
  4. In the Add assignments pane, assign the group to the IT Shop shelves.
  5. Save the changes.

To remove a group from individual shelves of the IT Shop

  1. In the Manager, select the Azure Active Directory | Groups category (non role-based login) category.

    - OR -

    In the Manager, select the Entitlements | Azure Active Directory groups (role-based login) category.

  2. In the result list, select the group.
  3. Select the Add to IT Shop task.
  4. In the Remove assignments pane, remove the group from the IT Shop shelves.
  5. Save the changes.

To remove a group from all shelves of the IT Shop

  1. In the Manager, select the Azure Active Directory | Groups (non role-based login) category.

    - OR -

    In Manager, select the Entitlements | Azure Active Directory groups (role-based login) category.

  2. In the result list, select the group.
  3. Select the Remove from all shelves (IT Shop) task.
  4. Confirm the security prompt with Yes.
  5. Click OK.

    The group is removed from all shelves by the One Identity Manager Service. All requests and assignment requests with this group, are canceled.

For more detailed information about requesting company resources through the IT Shop, see the One Identity Manager IT Shop Administration Guide.

Related topics

Additional tasks for managing Azure Active Directory groups

After you have entered the master data, you can run the following tasks.

The Azure Active Directory group overview

Use this task to obtain an overview of the most important information about a group.

To obtain an overview of a group

  1. Select the Azure Active Directory | Groups category.
  2. Select the group in the result list.
  3. Select the Azure Active Directory group overview task.

Adding Azure Active Directory groups to Azure Active Directory groups

Use this task to add a group to another group.

To assign groups directly to a group

  1. In the Manager, select the Azure Active Directory | Groups category.

  2. Select the group in the result list.

  3. Select the Assign groups task.

  4. In the Add assignments pane, assign the groups that are subordinate to the selected group.

    TIP: In the Remove assignments pane, you can remove the assignment of groups.

    To remove an assignment

    • Select the group and double-click .
  5. Save the changes.
Related Documents

The document was helpful.

Select Rating

I easily found the information I needed.

Select Rating