Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

Management Role

Description

Role Type

ACT-Person-Password-Self-Service

Grants users access to change password, enroll and other password self-service operations.

Activity

UI-Person-Password-Self-Service

Grants access to change password, enroll and other password self-service workflows and user interfaces.

Feature Set

IT Shop, My Tasks, and My Identity Self-Service Full Access

Grants full access for using the IT Shop, My Tasks, My Identity microservices

Role Bundle – Contains the below Management Roles

Dropdown macro
hardcodeWidth338
backgroundColor#0052CC
activeColor#ffffff
width53
hoverColor#307FC1
tabTypeno-icon
alignmentleft
[]
Dropdown macro
backgroundColor#fff
activeColor#0052CC
width530
hoverColor#307FC1#0065FF
tabTypeno-icon
alignmentcenterleft
[{"label":"ViewDropdown Management Roles1","id":"1","content":{"version":1,"type":"doc","content":[{"type":"bulletList","content":[{"type":"listItem","content":[{"type":"paragraph","content":[{"type":"text","text":"ACT-Person-Delegate-All"}]}]},{"type":"listItem","content":[{"type":"paragraph","content":[{"type":"text","text":"ACT-Person-SetAsApprover-All"}]}]},{"type":"listItem","content":[{"type":"paragraph","content":[{"type":"text","text":"UI-IT-Shop-MS-Azure-Admin-Role"}]}]},{"type":"listItem","content":[{"type":"paragraph","content":[{"type":"text","text":"UI-IT-Shop-MS-Computer"}]}]},{"type":"listItem","content":[{"type":"paragraph","content":[{"type":"text","text":"UI-MyTasks-Participant-Full"}]}]},{"type":"listItem","content":[{"type":"paragraph","content":[{"type":"text","text":"UI-IT-Shop-MS-Management-Role"}]}]},{"type":"listItem","content":[{"type":"paragraph","content":[{"type":"text","text":"UI-IT-Shop-MS-Azure-License"}]}]},{"type":"listItem","content":[{"type":"paragraph","content":[{"type":"text","text":"UI-MyIdentity-PermanentDelegations"}]}]},{"type":"listItem","content":[{"type":"paragraph","content":[{"type":"text","text":"UI-MyIdentity-EmailNotification-Settings"}]}]},{"type":"listItem","content":[{"type":"paragraph","content":[{"type":"text","text":"UI-IT-Shop-MS-Business-Role"}]}]},{"type":"listItem","content":[{"type":"paragraph","content":[{"type":"text","text":"UI-IT-Shop-MS-Shared-Folder"}]}]},{"type":"listItem","content":[{"type":"paragraph","content":[{"type":"text","text":"UI-IT-Shop-MS-Application-Role"}]}]},{"type":"listItem","content":[{"type":"paragraph","content":[{"type":"text","text":"UI-IT-Shop-MS-Mailbox"}]}]},{"type":"listItem","content":[{"type":"paragraph","content":[{"type":"text","text":"UI-MyIdentity-Full"}]}]},{"type":"listItem","content":[{"type":"paragraph","content":[{"type":"text","text":"UI-IT-Shop-MS-Common"}]}]},{"type":"listItem","content":[{"type":"paragraph","content":[{"type":"text","text":"UI-IT-Shop-MS-Risk"}]}]},{"type":"listItem","content":[{"type":"paragraph","content":[{"type":"text","text":"VIS-Application-All"}]}]},{"type":"listItem","content":[{"type":"paragraph","content":[{"type":"text","text":"VIS-Location-MyLocationsAndBelow"}]}]},{"type":"listItem","content":[{"type":"paragraph","content":[{"type":"text","text":"VIS-Person-MyOrg"}]}]},{"type":"listItem","content":[{"type":"paragraph","content":[{"type":"text","text":"VIS-IT-Shop-MS-API"}]}]},{"type":"listItem","content":[{"type":"paragraph","content":[{"type":"text","text":"VIS-Computer-All"}]}]},{"type":"listItem","content":[{"type":"paragraph","content":[{"type":"text","text":"VIS-Management-Role-All"}]}]},{"type":"listItem","content":[{"type":"paragraph","content":[{"type":"text","text":"VIS-AzLocalRole-All"}]}]},{"type":"listItem","content":[{"type":"paragraph","content":[{"type":"text","text":"VIS-Mailbox-All"}]}]},{"type":"listItem","content":[{"type":"paragraph","content":[{"type":"text","text":"VIS-Groups-All"}]}]},{"type":"listItem","content":[{"type":"paragraph","content":[{"type":"text","text":"VIS-BusinessRequestType-All"}]}]},{"type":"listItem","content":[{"type":"paragraph","content":[{"type":"text","text":"VIS-MyTasks-MS-API"}]}]},{"type":"listItem","content":[{"type":"paragraph","content":[{"type":"text","text":"VIS-MyIdentity-MS-API"}]}]},{"type":"listItem","content":[{"type":"paragraph","content":[{"type":"text","text":"VIS-Location-All-BusinessStructure"}]}]},{"type":"listItem","content":[{"type":"paragraph","content":[{"type":"text","text":"VIS-AzGlobalFunction-All"}]}]},{"type":"listItem","content":[{"type":"paragraph","content":[{"type":"text","text":"VIS-Shared-Credential-All"}]}]},{"type":"listItem","content":[{"type":"paragraph","content":[{"type":"text","text":"VIS-AzLocalFunction-All"}]}]},{"type":"listItem","content":[{"type":"paragraph","content":[{"type":"text","text":"UI-IT-Shop-MS-Azure-RBAC-Role"}]}]},{"type":"listItem","content":[{"type":"paragraph","content":[{"type":"text","text":"VIS-License-Pool-All"}]}]},{"type":"listItem","content":[{"type":"paragraph","content":[{"type":"text","text":"Vis-OrgRoleOrgZone-ALL"}]}]}]},{"type":"paragraph","content":[]}]}},{"label":"Dropdown 2","id":"2","content":{"content":[],"type":"doc","version":1}}]

Management Role

Access Granted by Management Role

UI-IT-Shop-MS-Full-Access

Inherits the below Access Levels from the parent Management Role Definition:

Workflow Access

Initiator Access Level for following workflows:

  • UpdatePersonDirectAssignment

  • UpdatePersonBusinessRoles

Control (User Interface) Access

Viewer Access Level for the following controls:

  • Application Process Control

  • Business Roles TCode Control

  • Business Roles Owners Attribute Control

  • Business Roles Advanced Search Control

  • Business Roles Role Approvers Attribute Control

  • Application Roles Resource System Attribute Control

  • Business Roles Name Attribute Control

  • Target System Control

  • Application Roles TCode Control

  • Application Roles Advanced Search Control

  • Shop for Target Person Control

  • Business Functions Control

  • Business Roles Parent Business Roles Attribute Control

  • Application Roles Owners Attribute Control

  • Application Roles High Level Classification Attribute Control

  • Business Domains Control

  • Business Roles High Level Classification Attribute Control

  • Application Roles Name Attribute Name

 Application Access

Viewer Access Level for the following applications:

  • IT Shop Microservice App

  • EmpowerID Web

Web Service Access

Executor Access Level for the following Web services:

  • All ITShop WebServices

  • AllRbacObjects

  • CartSubmissinoAPI.SubmitCart

 Pages and Reports Access

Viewer Access Level for the following pages and reports:

  • Groups Page (IT Shop)

  • Business Roles Page (IT Shop)

 

VIS-IT-SHOP-MS-API

Grants visibility to the base Web services required by all users of the IT Shop microservice.

Web Service Access

Executor Access Level for the following Web services:

  • BusinessFunctionsAPI

  • BusinessFunctionsAPI.GetChildrenByOrgZoneType

  • BusinessFunctionsAPI.GetOrgZonesByOrgZoneTypeTypes

  • BusinessLocationsAPI.GetOrgZoneTypes

  • BusinessLocationsAPI.Search

  • BusinessRolesAPI

  • BusinessRolesAPI.CheckAssignmentStatus

  • BusinessRolesAPI.GetApplicationRoleTemplates

  • BusinessRolesAPI.GetAssignedAppRolesByPersonGUID

  • BusinessRolesAPI.GetAssignedBusinessRolesByPersonGUID

  • BusinessRolesAPI.GetOrgRole

  • BusinessRolesAPI.GetOrgRoles

  • BusinessRolesAPI.GetSingleOrgRole

  • CartSubmissionAPI

  • CartSubmissionAPI.SubmitCart

  • CheckForSODAPI

  • CheckForSODAPI.GetAssigneesForOrgRoleType

  • GlobalSettingsAPI

  • GlobalSettingsAPI.GetConfigSetting

  • GroupsAPI

  • GroupsAPI.CheckAssignmentStatus

  • GroupsAPI.GetAssignedAppRolesByPersonGUID

  • GroupsAPI.GetAssignedMembershipByOrgRolesOrgZoneID

  • GroupsAPI.GetGroups

  • GroupsAPI.GetSingleOrgRole

  • GroupsAPI.GetTargetSystemsFilterdata

  • LocalizationAPI

  • LocalizationAPI.CountryHelpText

  • LocalizationAPI.GetByResourceSet

  • ProtectedAppResourceAPI

  • ProtectedAppResourceAPI.AlllowedSsoApplications

  • ProtectedAppResourceAPI.GetChildrenByProtectedApplication

...