Dynamic roles with incorrectly excluded identities
In the Manager, you can obtain an overview of all the dynamic roles with conflicting entries in the exclude list. This means that for at least one item in the list the following applies:
-
The dynamic role condition does not apply.
For example, this might occur if the dynamic role condition was changed after an identity was entered in the exclude list.
- OR -
-
The excluded identity is also assigned to the role in another way
such as through inheritance or direct assignment.
Check these entries and correct the assignments.
To check conflicting entries of departments, locations, or cost centers in the exclusion list
-
In the Manager, select the Organizations > Troubleshooting > Dynamic roles with potentially incorrect excluded identities category.
-
Select the dynamic role in the result list.
-
Select the Exclude identities task.
In the exclusion list you can see which identities are affected by the given conditions.
Related topics
Assign organizations
Use this task to map the relationships of a department, cost center of a location to other roles. This task has the same effect as assigning a department, cost center, or location on the role main data form. The assignment is entered in the respective foreign key column in the base table.
To assign a cost center or location to departments
-
In the Manager, select the Organizations > Cost centers or the Organizations > Locations category.
-
Select the role in the result list.
-
Select the Assign organizations task.
-
Select the Departments tab.
-
In the Add assignments pane, assign departments.
The selected role is primarily assigned to all departments as a cost center or location.
- Save the changes.
To assign a department or a location to cost centers
-
In the Manager, select the Organizations > Departments or the Organizations > Locations category.
-
Select the role in the result list.
-
Select the Assign organizations task.
-
Select the Cost centers tab.
-
In the Add assignments pane, assign cost centers.
The selected role is primarily assigned to all cost centers as a department or location.
- Save the changes.
To assign a department or a cost center to locations
-
In the Manager, select the Organizations > Departments or the Organizations > cost centers category.
-
Select the role in the result list.
-
Select the Assign organizations task.
-
Select the Locations tab.
-
In the Add assignments pane, assign locations.
The selected role is primarily assigned to all locations as a department or cost center.
- Save the changes.
Specifying inheritance exclusion for departments, cost centers, and locations
You can define conflicting roles to prevent identities, devices, or workdesks from being assigned to several roles at the same time and from obtaining mutually exclusive company resources through these roles. At the same time, specify which departments, cost centers, and locations are mutually exclusive. This means you may not assign these roles to one and the same identity (device, workdesk).
NOTE: Only roles, which are defined directly as conflicting roles cannot be assigned to the same identity (device, workdesk). Definitions made on parent or child roles do not affect the assignment.
To configure inheritance exclusion
To define inheritance exclusion for a departments
-
In the Manager, select the Organizations > Departments category.
-
Select the department in the result list.
-
Select Edit conflicting departments.
-
In the Add assignments pane, assign departments that are mutually exclusive to the selected department.
- OR -
In the Remove assignments pane, remove the departments that are no longer mutually exclusive.
- Save the changes.
To define inheritance exclusion for a cost center
-
In the Manager, select the Organizations > Cost centers category.
-
Select the cost center in the result list.
-
Select Edit conflicting cost centers.
-
In the Add assignments pane, assign cost centers that are mutually exclusive to the selected cost center.
- OR -
In the Remove assignments pane, remove the cost centers that are no longer mutually exclusive.
- Save the changes.
To define inheritance exclusion for a cost center
-
In the Manager, select the Organizations > Locations category.
-
Select the location in the result list.
-
Select Edit conflicting locations.
-
In the Add assignments pane, assign locations that are mutually exclusive to the selected location.
- OR -
In the Remove assignments pane, remove the locations that are no longer mutually exclusive.
- Save the changes.
Detailed information about this topic
Assigning extended properties to departments, cost centers, and locations
You can assign extended properties to departments, cost centers, and locations. Extended properties are meta objects, such as operating codes, cost codes, or cost accounting areas that cannot be mapped directly in One Identity Manager.
To set extended properties
-
In the Manager, select the Organizations > <role class> category.
-
Select the role in the result list.
-
Select Assign extended properties.
-
In the Add assignments pane, assign extended properties.
TIP: In the Remove assignments pane, you can remove assigned extended properties.
To remove an assignment
- Save the changes.
Related topics