The Usage Tab Creating a Password Policy

15 Managing Identity and Resource Information 15-1 15 Managing Identity and Resource Information This chapter describes managing users in Oracle Identity Manager Design Console. It contains the following sections: ■ Overview of User Management ■ Managing Organization Information ■ Viewing Resources Allowed or Disallowed for Users ■ Assigning Role Entitlements

15.1 Overview of User Management

The User Management folder provides tools to create and manage information about a companys organizations, users, roles, and resources. This folder contains the following forms: ■ Organizational Defaults : Use this form to view records that reflect the internal structure of your organization and to designate information related to these entities. ■ Policy History : Use this form to view user records that your employees require. ■ Roles : Use this form to view records for roles, called user groups in earlier releases of Oracle Identity Manager, to whom you can assign some common functionality.

15.2 Managing Organization Information

The Organizational Defaults form is in the User Management folder. You use this form to view records that reflect the structure of your organization and to enter and modify information related to organizational entities. An organization record contains information about an organizational unit, for example, a company, department, or branch. A suborganization is an organization that is a member of another organization, for example, a department in a company. The organization that the suborganization belongs to is referred to as a parent organization. You use the Organizational Defaults tab to specify default values for parameters on the custom process form for resources that can be provisioned for the current organization. Each process form is associated with a resource object that is allowed for the organization, or with a resource that has the Allow All option on the associated Resource Objects form selected. 15-2 Oracle Fusion Middleware Administrators Guide for Oracle Identity Manager The values that you provide on the Organizational Defaults tab become the default values for all users in the organization. Oracle recommends that you do not specify default values for passwords and encrypted parameters. Figure 15–1 shows the Organizational Defaults form. Figure 15–1 Organizational Default Form Table 15–1 describes the fields of the Organizational Default form.

15.3 Viewing Resources Allowed or Disallowed for Users

You use the Policy History form to view information about the resources that are allowed or disallowed for a user. There are two types of users in Oracle Identity Manager: ■ End-user administrators : This user can access Oracle Identity Manager Design Console and the Oracle Identity Manager Administrative and User Console. The system administrator sets permissions to enable end-user administrators to access a subset of the forms in Oracle Identity Manager Design Console. ■ End-users : This user can access only the Oracle Identity Manager Administrative and User Console and generally has fewer permissions than end-user administrators. Only resource objects that are defined as self-service on the Objects Allowed tab of the users organization are available for provisioning requests by using the Oracle Identity Manager Administrative and User Console. Table 15–2 shows this form. Table 15–1 Fields of the Organizational Defaults Form Field Name Description Organization Name Name of the organization. Type The classification type of the organization, for example, Company, Department, Branch. Status The current status of the organization Active, Disabled, or Deleted. Parent Organization The organization to which this organization belongs. If a parent organization is displayed in this field, this organization is displayed on the Sub Organizations tab for the parent organization. If this field is empty, this organization is a top-level organization.