Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

Identity Administration is the ability for designated individuals to perform user, group, shared folder, SharePoint, computer, and other object management tasks in a controlled manner using the Web interface and workflows of EmpowerID. Which objects a person may see and what management tasks they may perform against those objects is are controlled by EmpowerID's real-time RBAC / ABAC / PBAC hybrid security model. EmpowerID allows controlled Identity Administration through a single interface and security model without requiring delegation of native permissions in the various systems the objects they are managing reside. The key to developing an effective Identity Administration strategy involves uncovering the different types of "Personas" in your environment, classifying each by the objects they can see and the actions they can perform against them.

Users using the EmpowerID workflows or API may perform secure management of objects that exist in external systems and EmpowerID. Examples of external objects are Azure AD User Accounts, SAP Roles, File Shares, SharePoint sites, etc. Users may also manage objects that only exist in EmpowerID, like people, Management Roles, Business Roles, etc. In both cases, a real-time authorization engine leveraging RBAC, ABAC, and PBAC security controls who may manage which objects and which actions or tasks they may perform against those objects. The system also handles logging, automatic approval routing, and workflow task generation if a user tries users try an action they are not authorized to perform.

The bottom tier of the 3-tiered EmpowerID RBAC model is the Access Levels tier, which is EmpowerID's Technical Roles. Access Levels define which actions (operations) and which native system permissions (rights) , the recipient of the Access Level would be authorized to perform for any resources for which they have that Access Level. Access Levels can be directly assigned to people but are often assigned to RBAC Actors in one of the higher tiers (i.e., Business Roles and Locations, Management Roles, etc.)

...

Insert excerpt
IL:External Stylesheet
IL:External Stylesheet
nopaneltrue

...

User Administration

App Role / Group Administration

...