You are viewing an earlier version of the admin guide. For the latest version, please visit EmpowerID Admin Guide v7.211.0.0.

Skip to end of banner
Go to start of banner

IT Shop Management Roles

Skip to end of metadata
Go to start of metadata

You are viewing an old version of this page. View the current version.

Compare with Current View Page History

« Previous Version 8 Next »

EmpowerID restricts access to the IT Shop through the use of Management Roles. To access the IT Shop, users must be assigned to the appropriate roles. Management Roles are prefixed by their function in EmpowerID and include the following:

  • UI – Management Roles prefixed with UI grant users access to specific UI elements in the EmpowerID Web interface. An example of this type of role for Password Manager is UI-Person-Password-Self-Service. This role grants users access to the user interfaces and workflows for enrolling for self-service password reset and changing their own passwords.

  • VIS – Management Roles prefixed with VIS grant users the ability to see specific objects in EmpowerID. An example of this type of role for Password Manager is VIS-Person-Self. All users have this Management Role by default.

  • ACT – Management Roles prefixed with ACT grant users the ability to manage specific objects in EmpowerID. An example of this type of role for Password Manager is ACT-Password-Self-Service. This role grants users access to change passwords, enroll for password self-service reset, and perform other password self-service operations.

Roles needed to shop in the IT Shop

To shop for eligible resources in the IT Shop, users need to have one or more of the below Management Role assignments (based on the needed scope):

UI-IT-Shop-MS-Azure-Admin-Role

Management Role

Description

Role Type

UI-IT-Shop-MS-Application Role

Grants access to shop for Application Roles (Groups) in the IT Shop microservice app. The role specifically grants access to the following user interface controls, pages and reports, and web services:

Feature Set

UI-IT-Shop-MS-Azure-Admin-Role

Grants access to shop for Azure Admin Directory Roles in the IT Shop microservice app. The role specifically grants access to the following user interface controls, pages and reports, and web services:

Feature Set

UI-IT-Shop-MS-Azure-License

Grants access to shop for Azure Licenses in the IT Shop microservice app. The role specifically grants access to the following user interface controls, pages and reports, and web services:

UI-IT-Shop-MS-Azure-RBAC-Role

Grants access to shop for Azure RBAC Roles in the IT Shop microservice app. The role specifically grants access to the following user interface controls, pages and reports, and web services:

IT Shop, My Tasks, and My Identity Self-Service Full Access

Grants full access for using the IT Shop, My Tasks, My Identity microservices

Role Bundle – Contains the below Management Roles:

  • ACT-Person-Delegate-All

  • ACT-Person-SetAsApprover-All

  • UI-IT-Shop-MS-Azure-Admin-Role

  • UI-IT-Shop-MS-Computer

  • UI-MyTasks-Participant-Full

  • UI-IT-Shop-MS-Management-Role

  • UI-IT-Shop-MS-Azure-License

  • UI-MyIdentity-PermanentDelegations

  • UI-MyIdentity-EmailNotification-Settings

  • UI-IT-Shop-MS-Business-Role

  • UI-IT-Shop-MS-Shared-Folder

  • UI-IT-Shop-MS-Application-Role

  • UI-IT-Shop-MS-Mailbox

  • UI-MyIdentity-Full

  • UI-IT-Shop-MS-Common

  • UI-IT-Shop-MS-Risk

  • VIS-Application-All

  • VIS-Location-MyLocationsAndBelow

  • VIS-Person-MyOrg

  • VIS-IT-Shop-MS-API

  • VIS-Computer-All

  • VIS-Management-Role-All

  • VIS-AzLocalRole-All

  • VIS-Mailbox-All

  • VIS-Groups-All

  • VIS-BusinessRequestType-All

  • VIS-MyTasks-MS-API

  • VIS-MyIdentity-MS-API

  • VIS-Location-All-BusinessStructure

  • VIS-AzGlobalFunction-All

  • VIS-Shared-Credential-All

  • VIS-AzLocalFunction-All

  • UI-IT-Shop-MS-Azure-RBAC-Role

  • VIS-License-Pool-All

  • Vis-OrgRoleOrgZone-ALL

Management Role

Access Granted by Management Role

UI-IT-Shop-MS-Full-Access

Inherits the below Access Levels from the parent Management Role Definition:

Workflow Access

Initiator Access Level for following workflows:

  • UpdatePersonDirectAssignment

  • UpdatePersonBusinessRoles

Control (User Interface) Access

Viewer Access Level for the following controls:

  • Application Process Control

  • Business Roles TCode Control

  • Business Roles Owners Attribute Control

  • Business Roles Advanced Search Control

  • Business Roles Role Approvers Attribute Control

  • Application Roles Resource System Attribute Control

  • Business Roles Name Attribute Control

  • Target System Control

  • Application Roles TCode Control

  • Application Roles Advanced Search Control

  • Shop for Target Person Control

  • Business Functions Control

  • Business Roles Parent Business Roles Attribute Control

  • Application Roles Owners Attribute Control

  • Application Roles High Level Classification Attribute Control

  • Business Domains Control

  • Business Roles High Level Classification Attribute Control

  • Application Roles Name Attribute Name

 Application Access

Viewer Access Level for the following applications:

  • IT Shop Microservice App

  • EmpowerID Web

Web Service Access

Executor Access Level for the following Web services:

  • All ITShop WebServices

  • AllRbacObjects

  • CartSubmissinoAPI.SubmitCart

 Pages and Reports Access

Viewer Access Level for the following pages and reports:

  • Groups Page (IT Shop)

  • Business Roles Page (IT Shop)

 

VIS-IT-SHOP-MS-API

Grants visibility to the base Web services required by all users of the IT Shop microservice.

Web Service Access

Executor Access Level for the following Web services:

  • BusinessFunctionsAPI

  • BusinessFunctionsAPI.GetChildrenByOrgZoneType

  • BusinessFunctionsAPI.GetOrgZonesByOrgZoneTypeTypes

  • BusinessLocationsAPI.GetOrgZoneTypes

  • BusinessLocationsAPI.Search

  • BusinessRolesAPI

  • BusinessRolesAPI.CheckAssignmentStatus

  • BusinessRolesAPI.GetApplicationRoleTemplates

  • BusinessRolesAPI.GetAssignedAppRolesByPersonGUID

  • BusinessRolesAPI.GetAssignedBusinessRolesByPersonGUID

  • BusinessRolesAPI.GetOrgRole

  • BusinessRolesAPI.GetOrgRoles

  • BusinessRolesAPI.GetSingleOrgRole

  • CartSubmissionAPI

  • CartSubmissionAPI.SubmitCart

  • CheckForSODAPI

  • CheckForSODAPI.GetAssigneesForOrgRoleType

  • GlobalSettingsAPI

  • GlobalSettingsAPI.GetConfigSetting

  • GroupsAPI

  • GroupsAPI.CheckAssignmentStatus

  • GroupsAPI.GetAssignedAppRolesByPersonGUID

  • GroupsAPI.GetAssignedMembershipByOrgRolesOrgZoneID

  • GroupsAPI.GetGroups

  • GroupsAPI.GetSingleOrgRole

  • GroupsAPI.GetTargetSystemsFilterdata

  • LocalizationAPI

  • LocalizationAPI.CountryHelpText

  • LocalizationAPI.GetByResourceSet

  • ProtectedAppResourceAPI

  • ProtectedAppResourceAPI.AlllowedSsoApplications

  • ProtectedAppResourceAPI.GetChildrenByProtectedApplication

  • No labels