The Identity Manager User Application's Roles Based Provisioning Module provides an easy way to assign people to privileges in target systems through their role membership. The module allows you to easily ensure that employees have access to the resources they need to perform their jobs, but not more.
This milestone contains support for the Roles Based Provisioning Module.
The Role editor allows you to create and configure the roles you want to assign and manipulate in the Roles tab of the User Application. You use the editor to define the role details such as:
It is now possible to create Separation of Duties (SoD) constraints to manage potential conflicts between role assignments for the Roles Based Provisioning Module. You can define
It is now possible to configure the Role Subsystem for the Roles Based Provisioning Module in Designer. You can use the Role Configuration editor to define:
The Provisioning view now supports the Role
Catalog used by the Roles Based Provisioning Module. This includes
support for the following editors:
The Provisioning view also supports dynamic sub-containers for roles. A dynamic sub-container is a custom container created by the user. It can contain roles and other sub-containers. An example dynamic sub-container, called System, is shown in the screen shot above.
Dynamic sub-containers make it easier to define trustees for roles. You can define trustees on the sub-containter instead of defining the trustee on each role. In this release, you must use iManager to set the trustees on the sub-containers.
The Provisioning Style has been updated to include sections for roles, separation of duties and the role configuration.
All the category lists (Provisioning, Roles and Resource) now contain the string "Not translated - [CN]" in their list item labels when the user has not provided a value. This string is used when users open the Localize dialog for the list items and when users deploy the lists. Validation generates a warning that it is using a temporary "Not translated" string and that users should provide values.
The Provisioning Request Definition editor includes two workflows that support role approval and SoD constraint exception approval requests. To differentiate these workflows from standard workflows and from each other, the Process Type property has been added. Values are Normal, Role Approval and SoD Approval.
A new Role Binding activity has been added. This activity is used to either grant or deny either a Role or SoD approval request.
The Provisioning view now allows you to specify the name and display name of an object when pasting the object (into the same location).