Installed modules: | System Roles Module |
If you attest memberships in system roles, you can use the QER | Attestation | AutoRemovalScope | ESetAssignment configuration parameter to configure the automatic removal of system roles. After attestation approval has been denied, One Identity Manager checks which type of assignment was used for the user account to become a member in the system role.
Configuration parameter |
Effect when set |
---|---|
QER | Attestation | AutoRemovalScope | ESetAssignment | RemoveDirect |
Direct membership in the system role is removed. This removes all indirect assignments obtained by the identity through this system role. |
QER | Attestation | AutoRemovalScope | ESetAssignment | RemovePrimaryRole |
If the system role was inherited through a primary role, the role is withdrawn. This removes all indirect assignments obtained by the identity through this role. |
QER | Attestation | AutoRemovalScope | ESetAssignment | RemoveRequestedRole |
If the system role was inherited through a requested role, the role request is canceled or unsubscribed. This removes all indirect assignments obtained by the identity through this role. Set the desired behavior in the QER | Attestation | AutoRemovalScope | PWOMethodName configuration parameter. For more information, see Configuring withdrawal of entitlements. |
QER | Attestation | AutoRemovalScope | ESetAssignment | RemoveDelegatedRole |
If the system role was inherited through a delegated role, the delegation of this role is canceled or unsubscribed. This removes all indirect assignments obtained by the identity through this role. Set the desired behavior in the QER | Attestation | AutoRemovalScope | PWOMethodName configuration parameter. For more information, see Configuring withdrawal of entitlements. |
QER | Attestation | AutoRemovalScope | ESetAssignment | RemoveRequested |
If the system role was requested through the IT Shop, the request is canceled or unsubscribed. This removes all indirect assignments obtained by the identity through this system role. Set the desired behavior in the QER | Attestation | AutoRemovalScope | PWOMethodName configuration parameter. For more information, see Configuring withdrawal of entitlements. |
QER | Attestation | AutoRemovalScope | ESetAssignment | RemoveDirectRole |
If the system role was inherited through a secondary role (organization or business role), the identity's membership is removed from this role. This removes all indirect assignments obtained by the identity through this role. |
QER | Attestation | AutoRemovalScope | ESetAssignment | RemoveDynamicRole |
If the system role was inherited through a dynamic role, the identity is excluded from the dynamic role. This removes all indirect assignments obtained by the identity through this role. |
If you attest assignments to system roles, you can use the QER | Attestation | AutoRemovalScope | ESetHasEntitlement configuration parameter to configure automatic removal of assignments.
Configuration parameter |
Effect when set |
---|---|
QER | Attestation | AutoRemovalScope | ESetHasEntitlement | RemoveDirect |
Assignment of the company resource to a system role is removed. |
QER | Attestation | AutoRemovalScope | ESetHasEntitlement | RemoveRequested |
Assignment of the company resource to a system role requested by assignment request is unsubscribed. |
If you attest system role assignments to hierarchical roles, you can use the following configuration parameters to configure automatic removal of system roles.
Configuration parameter |
Effect when set |
---|---|
QER | Attestation | AutoRemovalScope | DepartmentHasESet | RemoveDirect |
The assignment of the system role to a department is removed. Therefore the system role is removed from all identities that inherit assignments from this department. |
QER | Attestation | AutoRemovalScope | ProfitCenterHasESet | RemoveDirect |
The assignment of the system role to a cost center is removed. Therefore the system role is removed from all identities that inherit assignments from this cost center. |
QER | Attestation | AutoRemovalScope | LocalityHasESet | RemoveDirect |
The assignment of the system role to a location is removed. Therefore the system role is removed from all identities that inherit assignments from this location. |
QER | Attestation | AutoRemovalScope | OrgHasESet | RemoveDirect |
The assignment of the system role to a business role is removed. Therefore the system role is removed from all identities that inherit assignments from this business role. |