Importing the matrix directly into One Identity Manager Table
The SecurityMatrix for Epic EMP template can be populated into the EPCMatrixEMPTemplate table using a custom solution implemented in the customer environment.
There could be scenarios where the customer would prefer alternate sources for security matrix import other than a csv file, for example a direct interface from the Epic Database or a custom application based on their implementation.
Viewing the Epic EMP template Security Matrix
The Security Matrix for Epic EMP template once imported could be viewed using One Identity Manager.
To view the imported matrix
- In One Identity Manager and navigate to the Epic connection that was created.
- In the Task menu, click View Security Matrix for Epic EMP template.
A grid is displayed with the Epic EMP template and the corresponding Property values for Identity.
Assignment of the Epic EMP template to Epic EMP user accounts
The Epic EMP user account can inherit Epic EMP templates from security matrix based on the properties mapped between the Identity and the matrix, provided that the Is Template Update Disabled flag for the user account is set to false.
The assignments inherited by the user from the Security Matrix has an XOrigin set to Matrix.
The User account Epic EMP template assignments are updated in the following cases
- An initial import of the data into the EPCMatrixEMPTemplate table.
- Subsequent updated to the Security Matrix for Epic EMP templates.
- Changes to the property values of the Identity linked to the user account.
- Change of the Identity liked to the Epic EMP user account.
NOTE: Assignment of applied and default Epic EMP templates by Security Matrix is disabled by default. To enable it the configuration parameter AutoSetAppliedEMPTemplate must be enabled.
Security Matrix for Epic EMP subtemplate
Security matrix for Epic EMP subtemplate is a table that consists of Epic EMP subtemplates grouped with one or more attributes of the Identity, which mostly consist of organizational attributes.