You are viewing an earlier version of the admin guide. For the latest version, please visit EmpowerID Admin Guide v7.211.0.0.
User Account and Group Management Roles
EmpowerID restricts access to accounts and groups through the use of Management Roles. To view and work with accounts and groups users must be assigned to the appropriate roles. Management Roles are prefixed by their function in EmpowerID and include the following:
UI — Management Roles prefixed with UI grant users access to specific UI elements in the EmpowerID Web interface.
VIS — Management Roles prefixed with VIS grant users the ability to see specific objects in EmpowerID.
ACT — Management Roles prefixed with ACT grant users the ability to manage specific objects in EmpowerID.
Roles needed by users to view and edit account profile information
To view and edit their basic account information, users need to have the following Management Role assignments:
Roles needed to add and remove accounts to and from groups
To manage the group assignments of user accounts, users need to have a combination of the following Management Role assignments (based on the needed scope).
Roles needed to create, update and delete accounts
To create, update and delete user accounts in EmpowerID, people need to have a combination of the following Management Role assignments (based on the needed scope):
In addition to the UI-Account-Object Administration Management Role, users need the following roles to create, update and delete AD user accounts. VIS-Accounts-AD — Grants visibility for all Active Directory user accounts. ACT-Account-Object-Administration-AD — Grants access to create, edit, and delete all Active Directory accounts. In addition to the UI-Account-Object Administration Management Role, users need the following roles to create, update and delete AWS user accounts. VIS-Accounts-AWS— Grants visibility for all AWS user accounts. ACT-Account-Object-Administration-AWS— Grants access to create, edit, and delete all AWS accounts. In addition to the UI-Account-Object Administration Management Role, users need the following roles to create, update and delete Linux user accounts. VIS-Accounts-Linux — Grants visibility for all Linux user accounts. ACT-Account-Object-Administration-All — Grants access to create, edit, and delete all user accounts, including accounts in Linux systems. In addition to the UI-Account-Object Administration Management Role, users need the following roles to create, update and delete Local Windows user accounts. VIS-Accounts-LocalWindows — Grants visibility for all Local Windows user accounts. ACT-Account-Object-Administration-All — Grants access to create, edit, and delete all user accounts, including accounts in Local Windows systems. In addition to the UI-Account-Object Administration Management Role, users need the following roles to create, update and delete Office 365 user accounts. VIS-Accounts-O365 — Grants visibility for all Office 365/Azure user accounts. ACT-Account-Object-Administration-O365 — Grants access to create, edit, and delete accounts in Office 365. In addition to the UI-Account-Object Administration Management Role, users need the following roles to create, update and delete SAP user accounts. VIS-Accounts-SAP — Grants visibility for all SAP user accounts. ACT-Account-Object-Administration-SAP — Grants access to create, edit, and delete accounts in SAP ABAP. |
Roles needed to create, update and delete groups
To create, update and delete groups in EmpowerID, people need to have a combination of the following Management Role assignments (based on the needed scope):
In addition to the UI-Group-Object Administration Management Role, users need the following roles to create, update and delete AD groups. VIS-Groups-All-AD — Grants visibility for all Active Directory groups. ACT-Group-Object-Administration-AD — Grants access to create, edit, and delete all Active Directory groups. In addition to the UI-Group-Object Administration Management Role, users need the following roles to create, update and delete groups in AWS. VIS-Groups-All-AWS— Grants visibility for all AWS groups. ACT-Group-Object-Administration-AWS— Grants access to create, edit, and delete all AWS groups. In addition to the UI-Group-Object Administration Management Role, users need the following roles to create, update and delete groups in Azure. VIS-Groups-All-Azure— Grants visibility for all Azure groups. ACT-Group-Object-Administration-All — Grants access to create, edit, and delete all groups, including groups in Azure. In addition to the UI-Group-Object Administration Management Role, users need the following roles to create, update and delete groups in Office 365. VIS-Accounts-O365 — Grants visibility for all Office 365 groups. ACT-Account-Object-Administration-O365 — Grants access to create, edit, and delete accounts in Office 365. In addition to the UI-Account-Object Administration Management Role, users need the following roles to create, update and delete SAP roles and profiles. VIS-Groups-SAP — Grants visibility for all SAP roles and profiles. ACT-Group-Object-Administration-All— Grants access to create, edit, and delete all groups, including those in SAP. In addition to the UI-Account-Object Administration Management Role, users need the following roles to create, update and delete group under the All IT Systems location. VIS-Groups-All-IT-Systems— Grants visibility for all groups under the All IT Systems location. ACT-Group-Object-Administration-All— Grants access to create, edit, and delete all groups, including those under the All IT Systems location. |
IN THIS ARTICLE