立即与支持人员聊天
与支持团队交流

Identity Manager On Demand Hosted - Company Policies Administration Guide

Company policies
One Identity Manager users for company policies Basic data for company policies Defining company policies Checking company policies Creating custom mail templates for notifications
Mitigating controls General configuration parameter for company policies

Assigning company policies

Use this task to assign company policies to the selected schedule that will run them. By default, a company policy is assigned to the "default schedule policies" schedule. Using the assignment form you can assign the selected schedule to any of the company polices.

To assign a schedule to a company policy

  1. Select the Company Policies > Basic configuration data > Schedules category.
  2. Select the schedule in the result list.
  3. Select Assign company policies.
  4. In the Add assignments pane, double-click the company policies you want to assign.
  5. Save the changes.

To change an assignment

  1. Select the Company Policies > Basic configuration data > Schedules category.
  2. Select the schedule in the result list.
  3. Select the Assign company policies task.
  4. Select the Show objects already assigned to other objects menu item in the assignment form's context menu.

    This shows company policies that are already assigned in other schedules.

  5. In the Add assignments pane, double-click on one of these company policies.

    The company policy is assigned to the currently selected schedule.

  6. Save the changes.
  7. To put the changes into effect, enable the working copy.
NOTE: Assignments cannot be removed. Company policies must be assigned a schedule. It is compulsory.
Related topics

Starting schedules immediately

To start a schedule immediately

  1. Select the Company Policies > Basic configuration data > Schedules category.
  2. Select the schedule in the result list.
  3. Select the Start immediately task.

    A message appears confirming that the schedule was started.

Attestors

Installed modules: Attestation Module

Employees that can be used to attest attestation procedures can be assigned to company policies. To do this, assign an application role for attestors to a company policy on the main data form. Assign employees to this application role that are authorized to attest company policies.

A default application role for attestors is available in One Identity Manager. You may create other application roles as required. For detailed information about application roles, see the One Identity Manager Authorization and Authentication Guide.

Table 7: Default application roles for attestors
User Tasks

Company policy attestors

Attestors must be assigned to the Identity & Access Governance | Company policies | Attestors application role.

Users with this application role:

  • Attest company policies and exception approvals in the Web Portal for which they are responsible.

  • Can view the main data for these company policies but not edit them.

NOTE: This application role is available if the module Attestation Module is installed.

To edit attestors

  1. Select the Company Policies > Basic configuration data > Attestors category.
  2. Select the Change main data task.

    - OR -

    Select an application role in the result list. Select the Change main data task.

    - OR -

    Click in the result list.

  3. Edit the application role's main data.
    Property Value
    Parent application role Assign the Identity & Access Governance | Company policies | Attestors application role or a child application role.
  4. Save the changes.
  5. Select the Assign employees task, to add members to the application role.
  6. In the Add assignments pane, assign employees.

    - OR -

    In the Remove assignments pane, remove employees.

  7. Save the changes.

Policy supervisors

Employees who are responsible for the contents of company policies can be assigned to these company policies. To do this, assign an application role for policy supervisors to a company policy on the main data form.

A default application role for policy supervisors is available in One Identity Manager. You may create other application roles as required. For detailed information about application roles, see the One Identity Manager Authorization and Authentication Guide.

Table 8: Default application role for rule supervisors
User Tasks

Policy supervisors

Policy supervisors must be assigned to the Identity & Access Governance | Company policies | Policy supervisors application role or another child application role.

Users with this application role:

  • Are responsible for the contents of company policies.

  • Edit working copies of company policies.

  • Enable and disable company policies.

  • Can calculation policies and view policy violations if required.

  • Assign mitigating controls.

To edit a policy supervisor

  1. Select the Company Policies > Basic configuration data > Policy supervisors category.
  2. Select the Change main data task.

    - OR -

    Select an application role in the result list. Select the Change main data task.

    - OR -

    Click in the result list.

  3. Edit the application role's main data.
    Property Value
    Parent application role Assign the Identity & Access Governance | Company policies | Policy supervisors application role or a child application role.
  4. Save the changes.
  5. Select the Assign employees task, to add members to the application role.
  6. In the Add assignments pane, assign employees.

    - OR -

    In the Remove assignments pane, remove employees.

  7. Save the changes.
相关文档

The document was helpful.

选择评级

I easily found the information I needed.

选择评级