Table of Contents

Search

  1. Preface
  2. Starting Data Archive
  3. System Configuration
  4. Database Users and Privileges
  5. Source Connections
  6. Target Connections
  7. Archive Store Configuration
  8. Datatype Mapping
  9. Database Optimization
  10. SAP Application Retirement
  11. z/OS Source Data Retirement
  12. Seamless Data Access
  13. Data Discovery Portal
  14. Security
  15. SSL Communication with Data Vault
  16. LDAP User Authentication
  17. Auditing
  18. Running Jobs from External Applications
  19. Salesforce Archiving Administrator Tasks
  20. Upgrading Oracle History Data
  21. Upgrading PeopleSoft History Data
  22. Data Archive Maintenance
  23. Appendix A: Datetime and Numeric Formatting
  24. Appendix B: Data Archive Connectivity

Administrator Guide

Administrator Guide

Nested Group Synchronization for Role Assignments

Nested Group Synchronization for Role Assignments

You can maintain roles in nested groups in the LDAP directory service. You may want to use nested groups for organizational purposes and to group similar types of roles. Attributes that you maintain at the group level apply to all roles within the group.
You may want to group roles by the type of roles that you commonly assign to users. For example, you may have several roles that you typically assign to users that perform administrator tasks. Then, you can assign users or groups of users to the group. By default, the user gets assigned to all of the roles that are within the group and any nested groups. Assigning roles to groups saves time as you avoid individually assigning roles to every user.
When you run the Sync with LDAP Server job, the job reviews all role assignments for users, including roles in nested groups. There is no limit to the amount of nested groups that you can have in one group.
For example, you can create the following structure in the LDAP directory service:
ILM Administrator Roles (Parent LDAP Security Group) ---Administrator role (ILM Role) ---Export Administrator role (ILM Role) ---ILM Tag Roles (Nested LDAP Security Group) ------Tag Administrator role (ILM Role) ------Tag Viewer role (ILM Role)
The ILM Administrator Roles group includes the Administrator role, the Export Administrator role, and the ILM Tag Roles nested group. The ILM Tag Roles group includes the Tag Administrator role and the Tag Viewer role.
You assign a user to the ILM Administrator Roles security group. The next time the user logs in to Data Archive, Data Archive adds the Administrator, Export Administrator, Tag Administrator, and Tag Viewer roles to the user account.

0 COMMENTS

We’d like to hear from you!