立即与支持人员聊天
与支持团队交流

Identity Manager 8.1.4 - IT Shop Administration Guide

Setting up an IT Shop solution
One Identity Manager users in the IT Shop Implementing the IT Shop Requestable products Preparing products for requesting Assigning and removing products Preparing the IT Shop for multi-factor authentication Assignment requests and delegating Creating IT Shop requests from existing user accounts, assignments, and role memberships Adding Active Directory and SharePoint groups to the IT Shop automatically Adding Privileged Account Management user groups to the IT Shop automatically
Approval processes for IT Shop requests
Approval policies for requests Approval workflows for requests Determining the effective approval policies Selecting responsible approvers Request risk analysis Testing requests for rule compliance Approving requests from an approver Automatically approving requests Approval by peer group analysis Gathering further information about a request Appointing other approvers Escalating an approval step Approvers cannot be established Automatic approval on timeout Cancel request on timeout Approval by the chief approval team Approving requests with terms of use Using default approval processes
Request sequence Managing an IT Shop
IT Shop base data Setting up IT Shop structures Setting up a customer node Deleting IT Shop structures Templates for automatically filling the IT Shop Custom mail templates for notifications Request templates
Resolving errors in the IT Shop Configuration parameters for the IT Shop Request statuses Examples of request results

Creating IT Shop requests from existing user accounts, assignments, and role memberships

You can create One Identity Manager requests for existing user accounts, membership in system entitlements, assignments to employees, and hierarchical roles when IT Shop goes into operation. One Identity Manager provides several methods to implement this. Using these methods, requests are created that are completed and approved. These requests can therefore be canceled at a later date. In addition to the initial request data, you can run a custom script from each method that sets other custom properties for a request.

Table 19: Methods for transforming direct assignments into requests

Method

Description

CreateITShopOrder (string CustomScriptName)

Creates a request from a direct assignment. This method can be applied to all tables used to find a UID_Person.

CreateITShopOrder (string uidOrgProduct, string uidPersonOrdered, string CustomScriptName)

Creates an assignment request from an assignment or membership. This method can be applied to all tables that cannot be used to find a UID_Person.

CreateITShopOrder (string uidOrgProduct, string uidWorkdeskOrdered, string uidPersonOrdered, string CustomScriptName)

Creates an assignment request from an assignment or membership and, in addition, saves a UID_WorkdeskOrdered with the request procedure.

CreateITShopWorkdeskOrder (string uidPerson, string CustomScriptName)

Creates a request for a workdesk from a direct assignment. This method can be applied to the WorkDeskHasApp, WorkDeskHasESet and WorkDeskHasDriver tables.

To run the methods

  1. Create a script in the Designer with the Script Editor to call the desired method.

    You can find an example script for calling a Customizer method in VB syntax on the One Identity Manager installation medium in the Modules\QBM\AddOn\SDK\ScriptSamples\03 Using database objects\11 Call database object methods.vb directory. You can use this example script as a template to create a script for call the methods described here.

  2. Run the script.

    You can use the script test from the Script Editor to do this.

For more information about creating scripts, see the One Identity Manager Configuration Guide.

Creating requests for employees

You can create requests for employees or memberships in system entitlements with CreateITShopOrder (string CustomScriptName). Prepare the IT Shop accordingly in order to create the requests.

To create requests from direct assignments to employees or memberships in system entitlements

  1. Prepare the company resources or system entitlements for use in the IT Shop.

  2. Assign the company resources or system entitlements to a shelf in the IT Shop.

  3. Link each user account for whose memberships requests are to be created with an employee.

  4. Add employees as customers to shops to which the company resources or system entitlements are assigned as products.

  5. (Optional): Create a script that populates other properties of the requests.

    • Pass the script name as a CustomScriptName parameter to the task.

  6. Create a script to run CreateITShopOrder (CustomScriptName string) for the affected tables.

One Identity Manager creates requests from direct assignments to employees in the following way:

  1. Determine employees and their assigned company resources.

  2. Determine shops assigned to company resources and employees.

  1. Create the requests with initial data.
  2. Execute custom scripts.
  3. Save the requests (entry in the PersonWantsOrg table).
  1. Assign employees to the product structure (entry in PersonInITShopOrg table).

  2. Transform direct company resource assignments into indirect assignments to employees (for example, in the PersonHasQERResource table).

One Identity Manager creates requests for memberships in system entitlements in the following way:

  1. Establish the user accounts and their memberships.

  2. Determine the affected employees.

  3. Determine the shops to which employees and the system entitlements are assigned.

  1. Create the requests with initial data.
  2. Execute custom scripts.
  3. Save the requests (entry in the PersonWantsOrg table).
  1. Assign employees to the product structure (entry in PersonInITShopOrg table).

  2. Transform direct company memberships into indirect memberships for affected user accounts (for example, in the ADSAccountInADSGroup table).

Related topics

Creating user account requests

To assign user accounts to employees, use One Identity Manager account definitions. You can request matching account definitions for existing user accounts linked to the employees through the IT Shop. To create these requests, you can use CreateITShopOrder (string CustomScriptName). This method can be used for all user account tables (for example, ADSAccount or SAPUser) and for the ADSContact, EX0MailBox, EX0MailContact, and EX0MailUser.

Prepare the IT Shop accordingly in order to create the requests.

To create requests for user accounts

  1. Create an account definition for the target system. Assign the account definition to the target system.

  2. Prepare the account definition for use in the IT Shop.

  3. Assign the account definition to a shelf in the IT Shop.

  4. Link the user account to an employee.

  5. Add employee as customers to shops to which the account definition is assigned as product.

  6. (Optional): Create a script that populates other properties of the requests.

    • Pass the script name as a CustomScriptName parameter to the task.

  7. Create a script that runs the method for the tables affected.

One Identity Manager creates requests for user accounts in the following way:

  1. Determine the valid account definition.

  2. Determine the affected employees.

  3. Determine the shops to which employees and the account definition are assigned.

  1. Create the requests with initial data.
  2. Execute custom scripts.
  3. Save the requests (entry in the PersonWantsOrg table).
  1. Assign employees to the product structure (entry in PersonInITShopOrg table).

  2. Transform any possible direct account definition assignments to indirect assignments (entry in PersonHasTSBAccountDef table).

Related topics

Creating workdesk requests

Requests for workdesks are created with CreateITShopWorkdeskOrder (string uidPerson, string CustomScriptName). Prepare the IT Shop accordingly in order to create the requests.

To create requests from assignments to workdesks

  1. Prepare the company resources (software, system role, or driver) for use in the IT Shop.

  2. Assign the company resources to a shelf in the IT Shop.

  3. Select an employee as requester for the assignment to workdesks.

    • Pass this employee's UID_Person as a uidPerson parameter to the task.

  4. Add the selected employee as a customer to the shops to which the company resources are assigned as products.

  5. (Optional): Create a script that populates other properties of the requests.

    • Pass the script name as a CustomScriptName parameter to the task.

  6. Create a script to run CreateITShopWorkdeskOrder (string uidPerson, string CustomScriptName) for the affected tables.

One Identity Manager creates requests for workdesk requests in the following way:

  1. Determine workdesks and their assigned company resources.

  2. Determine requester from the uidPerson parameter.

  3. Determine shops assigned to company resources and requester.

  1. Create the requests with initial data.
  2. Execute custom scripts.
  3. Save the requests (entry in the PersonWantsOrg table).
  1. Assign employees to the product structure (entry in PersonInITShopOrg table).

  2. Transform direct company resource assignments into indirect assignments to workdesks (for example, in the WorkDeskHasApp table).

Related topics
相关文档

The document was helpful.

选择评级

I easily found the information I needed.

选择评级