Enter user with 'Del. Management' authorisation

Via User Management -> Delegated Management to 'Unit Selection'.
Via User Management -> Delegated Management to 'Unit Selection'.

Select desired department/unit & 'Next' to 'User selection'.
Select desired department/unit & 'Next' to 'User selection'.

.
.


Comment
If "Strict-Onboarding" is configured for the corresponding access client in the portal properties, the "Mobile nummer" must be entered (mandatory field). This also applies to Bulk-Onboarding of new users (see section below Bulk-Onboarding Functionality).

Select the desired user & 'Next' to 'Manage permissions'.
Select the desired user & 'Next' to 'Manage permissions'.


Explaining the difference between the two tabs …(own permissions / roles to be delegated)

Tab 'Grant permissions'
In this tab, the administrator can assign individual roles or collective roles of the respective application to the user.

In addition, roles with attributes can be assigned at this point.
In addition, roles with attributes can be assigned at this point.


Explaining special case roles with attributes:
.
.


Tab 'Grant permissions for delegated administration'
In this tab, the administrator can activate various settings for the user in the role as (future) delegated administrator. From a technical point of view, this processing is comparable to the 'Add IDM role' in IDM.
.
.


  • Checkbox "Delegated Management of (Sub-)Units"
    "Delegated Administration of (Sub-)Units":
    If enabled, the IDM role DelegatedAdmin_SubUnit is assigned to the user.
  • Checkbox "Delegated Management of Users"
    "Delegated Administration of Users":
    If enabled, the IDM role DelegatedAdmin_User is assigned to the user.
  • Checkbox "Delegated Management of Permissions"
    "Delegated Administration of Permissions":
    If checked, the IDM role DelegatedAdmin_Permissions is assigned to the user. If the checkbox is activated, the roles/business roles that the Del. Administrator may assign to other users.
.
.


  • Checkbox "incl. substitution (further delegation of management rights to deputies possible)" "incl. Substitution": If checked, the user will be allowed to edit the 'Grant Delegated Management Permissions' tab.

Check before sending:

Show detailed information via function button 'Show more'
Show detailed information via function button 'Show more'

Permissions granted
Permissions granted

Delegated management rights granted
Delegated management rights granted

Details of the delegated management rights
Details of the delegated management rights


Send onboarding link or send notification email

.
.

.
.


Comment
Function button 'Send notification email / Send onboarding email' is only enabled if text is entered in the Reason for authorisation (traceability) field.

Final Notification:

.
.


Reset Onboarding

The onboarding reset for already onboarded users can be performed in the admin portal using the following option.
Image of the eIAM portal for delegated management with user selection and selection of the reset onboarding feature.
Feature: reset onboarding


Example: Onboarding email to user

.
.


Example: notification mail when permissions change

.
.


Manual path onboarding (print)

Describe in prose why this may be necessary....
.
.

.
.

Print
Print


Option: Save onboarding links in ...

.
.


Option: Send Onboarding Mail

Already described in 'Send onboarding link'.

Bulk-Onboarding Functionality

With this extension it is now possible to assign delegAdmin roles to the user directly during onboarding. The following delegAdmin roles can be specified per user in the extended .csv file.
.
.


Supported IDM DelegAdmin roles
  • DelegatedManager_User
  • DelegatedManager_Subunit
  • DelegatedManager_Permission
  • DelegatedManager_DelegMgmt_Permission

CSV file

Name Mandatory Example Explanation
firstName Yes Jon FirstName
lastName Yes Smith Name
email Yes jsmith@test.com E-mail address
language Yes en language
voucherCode Yes AB2D-EF7P format XXXX-XXXX, accepted characters ABCDEFGHJKLMNPQRSTUVWXYZ, accepted numbers 23456789
(not valid: character «I» «O» and numbers «1» «0»)
mobileNumber
                             
only for Strict-Onboarding 0041791234567 phone number
addressLine1 only for onboarding by letter Engehalde 22 street
addressLine2 only for onboarding by letter Information technology Inc additional information
postalCode only for onboarding by letter 3005 Postcode
city only for onboarding by letter Bern city
countryCode only for onboarding by letter ch country
additionalRoles No DelegatedManager_User
DelegatedManager_Subunit
DelegatedManager_Permission
DelegatedManager_DelegMgmt
_Permission

Default: none

One or more of the above supported IDM roles
unitExtId No 1234


Default: the unit selected at the start of
Bulk-Onboarding
ExtId of the Unit to which the user is to be added. Must be either the unit selected in the AdminPortal or a child unit of that unit
profile name No
                 
TestProfile If the profile name is defined in the CSV file (i.e. the value in the column for a row is not empty), it should take precedence over the email address, which could come from the OnboardingDataStorage function if it is enabled for the client.


If the onboardingDataStorage function is enabled and there is nothing in the profileName column for that row, the profile name should still be the email address.

Conditions for a successful execution of the extended Bulk-Onboarding

  1. only the supported IDM roles mentioned above are present
  2. the IDM roles are correctly formatted (correct separator)
  3. the executing administrator has the necessary rights to assign all requested IDM roles
If any of these conditions are not met, onboarding will not start and an error message will be displayed (the error message contains the line number and a reason text e.g. no rights).