ISE Identity Manager Delegated Admin


This tutorial is part of the Identity Manager track within the Identity Suite Essentials program.



Description

This tutorial covers basic delegated administration features of Identity Manager. A helpdesk user is create that has the Capability to do password management for user. An administrator is created that can only manage a specific Organization.

Top


Learning Objectives

After completing this tutorial, the following topics should be understood.

  1. Creating Organizations
  2. Assigning Capabilities to users
  3. Scoping users to specific Organizations

Top


Prerequisites

The following items must be completed before starting this tutorial.

Top


Setup

The following steps need to performed to enable the demonstration.

Section 1: Create Security Organization

Create a new Organization so that we can have a Delegated Admin be responsible for it. 

Note:  This organization will already exist if you completed module 2.
  1. Access the Admin Interface http://localhost:8080/idm and log in as: configurator / configurator
  2. Select the Accounts tab
  3. Select the List Accounts sub-tab
  4. Click on the -- New Actions -- Drop Down List
    Select New Organization
  1. In the Name Text Field, enter System Accounts
  2. Click the Save Button
Notice that the System Accounts Organization (Folder) is available.

Section 2: Create Help Desk Admin

The user created in this section will have the ability to Change and Reset passwords for user throughout the organization.

  1. Access the Admin Interface http://localhost:8080/idm and log in as: configurator / configurator
  2. Select the Accounts tab
  3. Select the List Accounts sub-tab
  4. Click on the -- New Actions -- Drop Down List
    Select New User
  1. Fill out the user attributes:
    • Account ID: helpdesk1
    • First Name: Help
    • Last Name: Desk1
    • Email: help.desk@example.com
    • Organization:  Top:System Accounts
    • Password/Confirm: Passw0rd
  2. Select the Security Tab
  1. In the Capabilities Multi Select, Assign the following:
    • Password Administrator
  2. For the Controlled Organizations, Assign Top
  3. Click the Save Button
    (bottom of the page)
  4. Click OK on the following summary page

Section 3: Create Security Admin

The user created in this section will have full admin capabilities but only for the Security Organization.

  1. Access the Admin Interface http://localhost:8080/idm and log in as: configurator / configurator
  2. Select the Accounts tab
  3. Select the List Accounts sub-tab
  4. Click on the -- New Actions -- Drop Down List
    Select New User
  1. Fill out the user attributes:
    • Account ID: secadmin1
    • First Name: Security
    • Last Name: Admin1
    • Email: security@example.com
    • Organization:  System Accounts
    • Password/Confirm: Passw0rd
  2. Select the Security Tab
  1. In the Capabilities Multi Select, Assign the following:
    • Account Administrator
  2. For the Controlled Organizations, Assign Top:System Accounts
  3. Click the Save Button
    (bottom of the page)
  4. Click OK on the following summary page

Top


Demonstration

After completing the setup above, the following steps should be performed to complete this tutorial.

Section 1: Help Desk Password Management

  1. Access the Admin Interface http://localhost:8080/idm and log in as: helpdesk1 / Passw0rd
  2. Select the Accounts tab
  3. Select the List Accounts sub-tab
  4. Things to notice ...
    • 1: There are less Admin Tab options
      (compared to Configurator)
    • 2: There are NO New Actions items
    • 3: Existing Users are NOT click-able links
  5. Check the Box in front of the jwayne user
  6. From the -- User Actions -- Drop Down List
    Select the Change Password item
  1. Change the Password Text Field to Password
  2. Change the Confirm Password Text Field to Password
  3. Make sure that the Check Boxes are SELECTED for:
    • Change Identity system user and all resource accounts
    • Account ID for Identity Manager
    • Account ID for Timecard
  4. Click the Change Password Button
  1. Notice the Results:
    • Password Change in Identity Manager
    • Password Changed in Timecard
  2. Click the OK Button

Section 2: Security Admin User Management

  1. Access the Admin Interface http://localhost:8080/idm and log in as: secadmin1 / Passw0rd
  2. Select the Accounts tab
  3. Select the List Accounts sub-tab
  4. Things to notice ...
    • There are less Admin Tab options
      (compared to Configurator)
    • The New Actions Drop Down ONLY has New User
    • This user can only see and control the Security Organization
  5. From the -- New Actions -- Drop Down select the New User item
  1. Fill out the user attributes:
    • Account ID: user1
    • First Name: Security
    • Last Name: Usesr1
    • Email: user1@example.com
    • Password/Confirm: Passw0rd
  2. Notice that the Organization Drop Down List can ONLY be Top:Security
  3. Click the Save Button
  4. Click OK on the following summary page
The user1 account has been created in the Top:Security Organization and can be managed by the secadmin1 delegated administrator.

Top


Resources

The following links provide more information:


Copyright (c) 2008-2009, Sun Microsystems, Inc.
All rights reserved

Enter labels to add to this page:
Please wait 
Looking for a label? Just start typing.

Sign up or Log in to add a comment or watch this page.


The individuals who post here are part of the extended Sun Microsystems community and they might not be employed or in any way formally affiliated with Sun Microsystems. The opinions expressed here are their own, are not necessarily reviewed in advance by anyone but the individual authors, and neither Sun nor any other party necessarily agrees with them.

Copyright 1994-2009 Sun Microsystems, Inc.
Powered by Atlassian Confluence
Sun Guidelines on Public Discourse Privacy Policy Terms of Use Trademarks Site Map Employment Investor Relations Contact