Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

IAM Shop Permission Levels are in EmpowerID constructs that represent permissions for specific resources in native systems for specific resources, such as applications, shared folders, mailboxes, and computers that organizations . Organizations can configure these permission levels to grant specific particular permissions against those to resources, such as “read-only” like "read-only" access for a shared folder or “local admin” "local admin" access for a computer. When users request access from the IAM Shop to a resource configured with IAM Shop Permission Levels, they will have the option to choose a permission level, as shown illustrated in the following image . below

...

In the above imagethis example, the user sees two permission levels for a computer, “Local Admin” and “Domain : "Local Admin" and "Domain Admin." Each of these levels is mapped to a specific group on in the native system that grants those permissions in the native systemthe corresponding permissions. For exampleinstance, if a user selects the IAM Shop Permission Level named “Local "Local Admin,” upon approval, " EmpowerID fulfills the request by adding the user to the group granting local admin rights on the computer.

...

EmpowerID includes default IAM Shop Permission Levels for shared folders, computers, and mailboxes that can be used to represent native permissions out of the box. However, you can create your own, naming them whatever makes sense for your custom permission levels with names that suit your environment. Once added to a resource, these custom permission levels will then appear to users shopping for those resources in the IAM Shop. For example, if you create an IAM Shop Permission Level for Computer X named “Power "Power User," users will see “Power User” "Power User" as a permission option for Computer X. The key to using IAM Shop Permission Levels effectively is to ensure ensuring they are mapped to the right appropriate objects in the native system that grant those permissions represent in the native systemthe represented permissions. Without proper mapping, IAM Shop Permission Levels are simply merely labeled options.

Macrosuite divider macro
dividerWidth100
dividerTypetext-with-icon
emoji{"id":"smile","name":"Smiling Face with Open Mouth and Smiling Eyes","short_names":["smile"],"colons":":smile:","emoticons":["C:","c:",":D",":-D"],"unified":"1f604","skin":null,"native":"😄"}
textColor#000000
dividerWeight3
labelPositionmiddle
textAlignmentcenter
iconColor#0052CC
iconSizemedium
fontSizemedium
textNext Steps
emojiEnabledfalse
dividerColor#DFE1E6
dividerIconbootstrap/BarChartSteps

...