This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Assign Group to elevated account only.

Ok so we have a number of Account Definitions for different classes of accounts, standard and elevated accounts.

The same is defined for groups. In which case, only elevated accounts should be allowed to be added to elevated groups. Similarly for regular groups.

How do I define what accounts can be added to which groups when assigning a resource to a person record to ensure that only the appropriate class of users from the account definition is assigned to the appropriate class of group.

For instance, if I have elevated groupA and assign it to a person record with standard account definition A, and elevated account definition A, how do I make sure that the elevated groupA is only assigned to the AD account associated with account definition A.

So far everything is working terrific, but I am a little off on how I should be thinking about this.

Thanks!

We are labbing this up in OIM 7.1 SP1. Any insights would be greatly appreciated.

  • Please have a look at the below section in the Target System Base Module Administration Guide. I have been able to accomplish this by the use of Categories. This helps selectively apply groups only to specific accounts when the categories match.

    Group Inheritance Based on Categories (please also see the Related Topics at the bottom of the page)
    support.oneidentity.com/.../21
  • There is also the concept of subidentities. Look through the documentation, including the Identity Management Base Module Administration Guide for more information.

    A subidentity allows you to set up special cases in One Identity Manager. If an
    employee has several user accounts in one target system that must be assigned to different
    groups, create a separate subidentity for each user account with a link to the main identity.