Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...


Div

Home / Authorization RBAC/ABAC / Management Roles / Current: Assigning Access Levels to Management Roles



Anchorassigning-access-levels-to-management-rolesassigning-access-levels-to-management-roles

EmpowerID Access Levels, also known as Resource Roles, are collections of "operational capabilities" and/or "native system rights" specific to a particular resource type, such as an account, group or mailbox. When you assign an Access Level to a Management Role, you give anyone assigned membership in the Management Role the ability to perform those operations or tasks against a selected resource.

anchor

to-assign-access-levels-to-management-rolesto-assign-access-levels-to-management-roles

To assign Access Levels to Management Roles

From


  1. In the Navigation Sidebar of the EmpowerID Web interface,
navigate to the Delegations Management page by expanding
  1. expand Identities and
clicking
  1. click Manage Delegations.
Select
  1. On the Actor Delegations tab
. Image Removed Select Management Role from the Assignee Type drop-down, type the
  1. , drop down the Assignee Type and select Management Role.
  2. Enter the name of the Management Role to

which you are delegating
  1. delegate access to in the Enter a Management Role Name to Search field and

then
  1. click the tile for

that Management Role.
  1. the role.

    Info

    In the following image, the Navigation Sidebar has been collapsed to conserve screen real estate.

Image Removed Select By Location from the Assignment Type drop-down

  1. Image Added

  2. Drop down the Assignment Type and select By Location. Selecting By Location gives the Management Role access
over
  1. to all resources of a resource type in a location and
the
  1. all its child locations
of that location
  1. .
From
  1. In the Assignments grid, click the Add Assignments (+) button.
Image Removed


  1. Image Added

  2. In the Grant Access dialog that appears,
do
  1. select the
following:Select the
  1. resource type for which
you want
  1. to give the Management Role an access level.
In our example, we are selecting
  1. This example selects the Computer resource type.
Underneath
  1. Under For Resource in or Below, click the Select a Location link, and in the Location Selector that appears, search for and select the location in which you want the Access Level to have effect.

    Image Added

  2. Click Save to close the Location Selector.
Select
  1. Drop down the Access Level
you want
  1. and select the one to assign to the Management Role
from the Access Level drop-down. In our example, we have selected
  1. . This example uses the Administrator Access Level. This gives anyone who is assigned to the Management Role all of the EmpowerID Operations and native system rights delegated to the Management Role.
  2. Optionally,
tick
  1. select Time Constraint
if you want to
  1.  to add a time constraint to the Access Level assignment. When this option is selected,
you set the date and time ranges by clicking
  1. click in the Valid From and Valid To fields and
picking the appropriate values from the Calendar.
  1. pick Calendar values to set date and time ranges.

    Image Added

  2. Click Save.

    Image Added
Repeat step 6

  1. This adds the Access Level assignment to the Shopping Cart.

    Image Added

  2. Repeat for each Access Level
you want
  1. to assign to the Management Role Definition
. When
  1. , and when you have
completed
  1. finished adding Access Level assignments, click the Shopping Cart icon, type a reason for the assignments in the cart dialog and
then
  1. click Submit.
Image Removed
  1.  

    Image Added



Info
iconfalse
titleRelated

...

Content


Rw ui expands macro


Rw ui expand macro
titleConcepts

Understanding EmpowerID RBAC

...


Rw ui expand macro
titleAdministrative Procedures

...

Creating Management Role Definitions

Assigning Access Levels to Management Role Definitions

Cloning Management Role Definitions

Creating Management Roles

Assigning Management Roles to Users

Publishing Management Roles to the IT Shop

Cloning Management Roles

Shipping Management Roles