Chat now with support
Chat with Support

Identity Manager 8.2.1 - Business Roles Administration Guide

Managing business roles
One Identity Manager users for business roles Hierarchical role structure basic principles Basic principles for assigning company resources Basics of calculating inheritance Preparing business roles for company resource assignments Base data for business roles Creating and editing business roles Assigning employees, devices, and workdesks to business roles Assigning business roles to company resources Analyzing role memberships and employee assignments Setting up IT operational data for business roles Creating dynamic roles for business roles Assign organizations Defining inheritance exclusion for business roles Assigning extended properties to business roles Creating assignment resources for application roles Dynamic roles for business roles with incorrectly excluded employees Reports about business roles
Role mining in One Identity Manager

Working with the Analyzer program

Use the Analyzer to automatically detect and analyze data correlations in the database. For example, this information can be used to replace direct permissions assignments with indirect assignments therefore reducing the administration effort.

Analyzer menu items

Table 17: Meaning of items in the menu bar

Menu

Menu item

Meaning

Shortcut

Database

New connection

Establishes a database connection.

Ctrl + Shift + N

Save to database

Changes to the data are saved to the connected One Identity Manager database.

Ctrl + Shift + S

Settings

For configuring general program settings.

Exit

Exits the program.

Alt + F4

Analysis

Previous assignment

Jumps to previous employee/permissions assignment.

Ctrl + U

Next assignment

Jumps to next employee/permissions assignment

Ctrl + D

Parent cluster

Swaps to parent cluster in the hierarchy.

Ctrl + P

Reanalyze

Reruns the analysis.

F9

Help

Analyzer help

Open the help program.

F1

Info

Shows the version information for program.

Analyzer program settings

To change the program settings in the Analyzer

  1. In the Analyzer, select the Database > Settings menu item.

  2. Customize the following settings.

    • Language: Language used for formatting data, such as date formats, time formats, and number formats.

    • Other user interface language:Language for the user interface. The initial program login uses the system language for the user interface. Changes to the language settings take effect after the program has been restarted.The language is set globally for all One Identity Manager programs, which means the language setting does not have to be configured for each program individually.

    • Automatically close analysis information window on completion: If this option is set and analyses are predefined, the information window is closed at the end of the analysis. If the option is not set, the information window is shown. Click the Finished button to close the window.

    • Show permissions weighting: Set this option to additionally display a weighting for the permissions.

    • Role naming template: Define a template for role names. This is used when to format new role names in predefined analysis methods.

      The template support following variables:

      %sequence%: Sequential number

      %object%: Name of the first object in the cluster

      %property%: Name of the first property in the cluster

  3. Save the settings with OK.

Running an analysis in the Analyzer

Use the Analyzer to perform the following steps:

  1. Specify the analysis method.

    • Selecting analysis data using the wizard: The initial data is collected using a wizard.

    • Active Directory Employee Permissions: The permissions of all employees with Active Directory group memberships are analyzed.

      NOTE: Analysis methods are available if the Active Directory Module is installed.

    • Active Directory Employee Permissions and Departments: The permissions of all employees with Active Directory group memberships are analyzed. Departments with Active Directory groups are also included in the analysis.

      NOTE: Analysis methods are available if the Active Directory Module is installed.

    • LDAP Employee Permissions: The permissions of all employees with LDAP group memberships are analyzed.

      NOTE: Analysis methods are available if the LDAP Module is installed.

  2. Verify the analysis results.

  3. Create a new business role if required and assign the employees. Add the suggested changes to the One Identity Manager database.

Detailed information about this topic
Related Documents

The document was helpful.

Select Rating

I easily found the information I needed.

Select Rating