Meeting Prerequisites and System Requirements 15
2.4 Granting Rights to the Role Mapping Administrator
UsersmusthaveaspecificsetofrightsintheIdentityVaultandspecificroleassignmentsintheRoles
BasedProvisioningModuletousetheRoleMappingAdministrator.
ThebestpracticeistocreateauserthatisusedforadministrationoftheRoleMapping
Administrator.Allotherusersthatuse
theRoleMappingAdministratorshouldhavetheirrights
limitedtomatchtheirjobduties.
Section 2.4.1,“IdentityVaultRightsforAdministration,”onpage 15
Section 2.4.2,“RolesBasedProvisioningModuleAssignmentsforAdministration,”onpage 16
Section 2.4.3,“RequiredRightsfortheRoleMapping Administrator,”onpage 16
2.4.1 Identity Vault Rights for Administration
AnadministrativeuserneedsthefollowingminimalrightstousetheRoleMappingAdministrator:
BrowseentryrightssotheycanselectobjectsintheconfigurationpaneloftheRoleMapping
Administrator.Forexample,theRootUsercontainer,DriverDiscoveryDN,andtheUser
ApplicationdriverDN.
Browseentryandreadrights
ontheuserscontainedwithintheRootUsercontainerdefinedin
theconfigurationpaneloftheRoleMappingAdministrator.Thelistofpotentialroleownersis
derivedbytheserights.
BrowseentryrightsontheactiveDriverSetobjectthatislocatedundertheDriverDiscoveryDN
asdefinedin
theRoleMappingAdministratorconfigurationpanel.
Inheritedbrowserightsandreadattributerightsonthedriversthatparticipateinrolemapping.
TheRoleMapping Administratorneedsaccesstotheentitlementsandentitlementconfiguration
objectsthatarecontainedwithinthedriversthatparticipateinrolemapping.
Inheritedbrowseentryandreadattribute
rightsontheUserApplicationdriver.TheRole
MappingAdministratorneedsaccesstoDALcategorydefinitions,roleconfigurationobjects,
androledefinitioncontainers.
InheritablesupervisorrightstotheRoleDefs.RoleConfig.AppConfig,
ResourceDefs.RoleConfig.AppConfigandResourceAssociations.RoleConfig.AppConfig
containerswithintheUAD.Allroleandresourceadds,modifies,anddeletesaredonewith
theserights.Rights
canbepareddownasneeded.
Youcanmaketheseassignmentstospecificusersoryoucanmaketheassignmentstoagroupora
container,thenassignuserstothegrouporadduserstothecontainer.
1 LogintoiManagerasanadministrativeuserforyourIdentityVault.
2 SelectViewObjectsonthetoolbar,thenbrowsetoandselecttheuser,group,orcontaineryou
wanttoassignrightsto.
3 Selecttheobject,thenclickActions>ModifyTrust ees.
4 Addtherightsasdefinedabove,thenclickOKtosavethechanges.