For example, if you are a user administrator, then all operations such as create user, modify user, grant account, enable user account, and so on are direct operations. Similarly, if you have been assigned the User Viewer admin role, then operations such as create user, enable user, delete user, grant role, revoke entitlements, and so on result in a request being created.
See below table for various Request or Direct Operations that are allowed based on the type of Role in OIM.
The Help Desk role is an interesting one, it has capabilities for both operations (Direct and Request based) - for example, Change User Password can be done by the Help Desk role via Direct operation, whereas in order to Enable a User, the Help Desk user will have to invoke a Request based operation. In other words Help Desk role/user cannot directly enable a user. However as you can see in above table, the User Administrator Role can directly Enable a user.
Comments
Post a Comment