Modifying Organization Attributes Viewing and Modifying Organizations

Managing Organizations 13-11

3. Click OK.

13.2.6 Managing Administrative Roles

The organization details page allows you to view and define a list of administrative roles and associated permissions that can administer the selected organization. To assign administrative roles to an organization, you must have the appropriate permission to create an organization. To assign permission to create organization:

1. On the role detail page for the role to which you want to assign administrative

privileges for organizations, click Data Object Permissions. The Role Details Permissions page is displayed.

2. Click Assign. The Assign Permissions page is displayed with a list of permission

names that you can select to assign the permissions to the role.

3. For the Organizations permission, select the Allow Insert option. This grants the

create organization permission to the orgadmin role. Then select the Assign option to the right of the Organizations permission.

4. Click Assign. A message is displayed asking for confirmation.

5. Click Confirm Assign. The permission is assigned to the role.

To assign administrative roles to an organization: 1. Open the Administrative Roles page by selecting any one of the following: ■ In the organization simple search result, select an organization. From the Actions menu, select Administrative Roles. ■ In the Browse tab on the left pane, select an organization. From the Actions menu, select Administrative Roles. ■ In the organization detail page, click Administrative Roles. 2. On the Administrative Roles page, in the Filter By Role Name, enter a search criterion to search for administrative roles that can administer the organization. Then, click Search. A list of roles with associated permissions are displayed.

3. To unassign any role from the organization, select the Unassign option to the right

of the administrative role, and click Unassign. 4. To assign an administrative role to the organization:

a. Click Assign. The Assign page is displayed with a list of available roles.

You can filter the role names by entering a search criteria in the Filter By Role Name box, and clicking Find. Note that the Read options are selected by default for all the roles. Note: You can enable an organization only if you have the Write permission for that organization. Note: The Insert permission is a prerequisite to Write and Delete permissions. Expanding the Insert permission allows you to create new organizations. The Write permission allows to update, enable, and disable organizations. The Delete permission enables to delete the organization. 13-12 Oracle Fusion Middleware Users Guide for Oracle Identity Manager

b. Select the Write, Delete, and Assign options for the administrative roles to

provide write, delete, and assign administrative permissions respectively.

c. Click Assign.

5. To update permissions for the administrative roles:

a. Click Update Permissions. The Update page is displayed with a list of

administrative roles, whose permissions you can modify. You can filter the role names by entering a search criteria in the Filter By Role Name box, and clicking Find. Note that the Read options are selected by default for all the roles.

b. Select or deselect the Write and Delete options for the administrative roles to

modify the write and delete permissions respectively.

c. Click Update.

6. When finished, close the Administrative Roles page. Figure 13–8 shows the Administrative Roles page. Figure 13–8 Assign Administrative Roles

13.2.7 Managing Permitted Resources

The Permitted Resources page allows you to assign and update a list of permitted resources to the users of the selected organization. 1. To assign permitted resources to the users in the selected organization: a. In the Browse tab on the left pane, select an organization. From the Actions menu, select Open.

b. In the organization detail page, click Permitted Resources.

c. In the Permitted Resources page, select the resources and click Assign.

2. To update the resources allowed to the selected organization: