To perform tasks and to access data in Data Archive, you must assign users to roles. Roles determine the tasks that users can perform or the data that users can access. The way you assign roles to users depends on if you enable role assignment synchronization. You enable role assignment synchronization in the
conf.properties
file.
When you run the Sync with LDAP Server job, the job assigns the User system-defined role to the user account. You need the User role to log in to Data Archive. You need to assign any relevant additional roles to the user. You can assign roles to users in the LDAP directory service, or you can assign roles in Data Archive after you synchronize users.
If you enable role assignment synchronization, then you maintain role assignments in the LDAP directory service. You add roles to users and maintain subsequent role changes in the LDAP directory service. The role assignments are synchronized when users log in to Data Archive. You can view the role assignments when you view the user account in Data Archive.
If you do not enable role assignment synchronization, then you maintain role assignments in Data Archive after you synchronize users. You add roles directly to the user account after the initial user synchronization. You maintain any subsequent role changes in Data Archive.