Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

As best practice, we suggest connecting the UMS with the user accounts of the Active Directory. You maintain the user and group accounts in the Active Directory only. In the UMS, you assign rights to the imported groups.


Drawio
border1
baseUrlhttps://igel-jira.atlassian.net/wiki
diagramNameUser Authorization Rules
width600
zoom1
pageId74450017
custContentId74778772
lbox1
diagramDisplayNameUser Authorization Rules
contentVer1
revision1

Transferring Active Directory groups to the UMS and assigning permissions and roles to them:

Include PageENLITEUMSP:_Icon_handlungsaufforderung.pngENLITEUMSP:_Icon_handlungsaufforderung.pngClick UMS Administration > Global Configuration > Active Directory / LDAP to integrate your Active Directory.

Info

You may import Administrative Users / UMS administrators from an Active Directory as well as from an LDAP.

Include PageENLITEUMSP:_Icon_handlungsaufforderung.pngENLITEUMSP:_Icon_handlungsaufforderung.pngIn the UMS console click System > Administrator accounts > Import, to import groups from the tree of your Active Directory.

Info

The successful import of a group cannot be undone. You have to manually delete the wrongly created UMS group in the "Administrator account" management. The name of the imported Active Directory group is taken from the account.

Include PageENLITEUMSP:_Icon_handlungsaufforderung.pngENLITEUMSP:_Icon_handlungsaufforderung.pngAssigning roles to groups in the IGEL UMS on the basis of authorization rules:

  • Click System > Administrator accounts > Groups > Edit to directly assign general group rights.

  • Assign object-related access rights via object permissions, choosing Access Control in the context menu of any object.


This way, you can assign certain roles to administrators of the UMS according to their group memberships.

Please note:

  • Permissions are inherited from a parent directory to a child directory or to a subordinated object.

  • It is possible to change indirect rights, i.e. rights which are given by group assignment. However, directly assigned rights take precedence over indirectly assigned rights.

  • An administrator can be a member of different groups and receives the corresponding rights. If they are contradictory, the deprivation of a right takes precedence over the permission. If a prohibition for an action or an object of a group is issued, it will override any number of rights from other groups.

  • Click Effective Rights to get more details about the rules collection, for example if a permission was given directly or if it was assigned by a group or by an inheritance within a tree structure.