Enter user with 'Del. Management' authorisation
-
- Via User Management -> Delegated Management to 'Unit Selection'.
-
- Select desired department/unit & 'Next' to 'User selection'.
-
- .
Comment
If "Strict-Onboarding" is configured for the corresponding access client in the portal properties, the "Mobile nummer" must be entered (mandatory field). This also applies to Bulk-Onboarding of new users (see section below Bulk-Onboarding Functionality).
-
- Select the desired user & 'Next' to 'Manage permissions'.
Explaining the difference between the two tabs …(own permissions / roles to be delegated)
Tab 'Grant permissions'
In this tab, the administrator can assign individual roles or collective roles of the respective application to the user.
-
- In addition, roles with attributes can be assigned at this point.
Explaining special case roles with attributes:
-
- .
Tab 'Grant permissions for delegated administration'
In this tab, the administrator can activate various settings for the user in the role as (future) delegated administrator. From a technical point of view, this processing is comparable to the 'Add IDM role' in IDM.
-
- .
- Checkbox "Delegated Management of (Sub-)Units"
"Delegated Administration of (Sub-)Units":
If enabled, the IDM role DelegatedAdmin_SubUnit is assigned to the user. - Checkbox "Delegated Management of Users"
"Delegated Administration of Users":
If enabled, the IDM role DelegatedAdmin_User is assigned to the user. - Checkbox "Delegated Management of Permissions"
"Delegated Administration of Permissions":
If checked, the IDM role DelegatedAdmin_Permissions is assigned to the user. If the checkbox is activated, the roles/business roles that the Del. Administrator may assign to other users.
-
- .
- Checkbox "incl. substitution (further delegation of management rights to deputies possible)" "incl. Substitution": If checked, the user will be allowed to edit the 'Grant Delegated Management Permissions' tab.
Check before sending:
-
- Show detailed information via function button 'Show more'
-
- Permissions granted
-
- Delegated management rights granted
-
- Details of the delegated management rights
Send onboarding link or send notification email
-
- .
-
- .
Comment
Function button 'Send notification email / Send onboarding email' is only enabled if text is entered in the Reason for authorisation (traceability) field.
Final Notification:
-
- .
Reset Onboarding
The onboarding reset for already onboarded users can be performed in the admin portal using the following option.-
- Feature: reset onboarding
Example: Onboarding email to user
-
- .
Example: notification mail when permissions change
-
- .
Manual path onboarding (print)
Describe in prose why this may be necessary....-
- .
-
- .
Option: Save onboarding links in ...
-
- .
Option: Send Onboarding Mail
Already described in 'Send onboarding link'.Bulk-Onboarding Functionality
With this extension it is now possible to assign delegAdmin roles to the user directly during onboarding. The following delegAdmin roles can be specified per user in the extended .csv file.-
- .
Supported IDM DelegAdmin roles
- DelegatedManager_User
- DelegatedManager_Subunit
- DelegatedManager_Permission
- DelegatedManager_DelegMgmt_Permission
CSV file
| Name | Mandatory | Example | Explanation |
|---|---|---|---|
| firstName | Yes | Jon | FirstName |
| lastName | Yes | Smith | Name |
| Yes | jsmith@test.com | E-mail address | |
| language | Yes | en | language |
| voucherCode | Yes | AB2D-EF7P | format XXXX-XXXX, accepted characters ABCDEFGHJKLMNPQRSTUVWXYZ, accepted numbers 23456789 (not valid: character «I» «O» and numbers «1» «0») |
| mobileNumber | only for Strict-Onboarding | 0041791234567 | phone number |
| addressLine1 | only for onboarding by letter | Engehalde 22 | street |
| addressLine2 | only for onboarding by letter | Information technology Inc | additional information |
| postalCode | only for onboarding by letter | 3005 | Postcode |
| city | only for onboarding by letter | Bern | city |
| countryCode | only for onboarding by letter | ch | country |
| additionalRoles | No | DelegatedManager_User DelegatedManager_Subunit DelegatedManager_Permission DelegatedManager_DelegMgmt _Permission Default: none | One or more of the above supported IDM roles |
| unitExtId | No | 1234 Default: the unit selected at the start of Bulk-Onboarding | ExtId of the Unit to which the user is to be added. Must be either the unit selected in the AdminPortal or a child unit of that unit |
| profile name | No | TestProfile | If the profile name is defined in the CSV file (i.e. the value in the column for a row is not empty), it should take precedence over the email address, which could come from the OnboardingDataStorage function if it is enabled for the client. If the onboardingDataStorage function is enabled and there is nothing in the profileName column for that row, the profile name should still be the email address. |
Conditions for a successful execution of the extended Bulk-Onboarding
- only the supported IDM roles mentioned above are present
- the IDM roles are correctly formatted (correct separator)
- the executing administrator has the necessary rights to assign all requested IDM roles