Organization Entity Definition Select any one of the following options:

Managing Organizations 13-5

13.2.2 Browsing Organizations

You can browse data in the Organizations section in Oracle Identity Manager Administration. The browse functionality is available in the left pane of the UI. Using the browse operation, you can navigate through the organization tree in the system, starting at the root organization. If there are multiple organization trees, then all the trees are displayed. Each tree starts at a root organization node, which has no parent organization. The users defined in the organization are not displayed as nodes in the tree. To browse through organizations, in the left pane of Oracle Identity Manager Administration, under the Browse tab, click Organization. All the organizations in Oracle Identity Manager are displayed in the browse list, as shown in Figure 13–4 : Figure 13–4 Organization Browse List The organization browse list shows the organizations trees with the root and child organizations. In the organization browse list, you can perform the following: ■ Create an organization. See Creating an Organization on page 13-5. ■ Open the details of an organization. See Viewing and Modifying Organizations on page 13-7. ■ Delete an organization. See Deleting an Organization on page 13-13. ■ Manage administrative roles: See Managing Administrative Roles on page 13-11.

13.2.3 Creating an Organization

You create an organization by using the Create Organization page. You can access this page only if you are authorized to create an organization. To create an organization: 1. Open the Create Organization page. To do so, perform any one of the following: ■ In the Welcome page of Oracle Identity Manager Administration, under Organizations, click Create New Organization. ■ In the left pane, click the Browse tab. Under Organizations, from the Action menu, select Create. You can also click the Create icon on the toolbar. Note: You are allowed to create an organization only if you have the Create Organization privilege for one or more organizations. 13-6 Oracle Fusion Middleware Users Guide for Oracle Identity Manager ■ In the left pane, click the Search Results tab with Organizations selected in the search list. From the Actions menu, select Create. You can also click the Create icon on the toolbar. ■ In the Advanced Search: Organization page, from the Actions menu, select Create Org , or click Create on the toolbar. Figure 13–5 shows the Create Organization page. Figure 13–5 The Create Organization Page 2. Enter values in the fields in the Create Organization page. Table 13–2 lists the fields in the Create Organization page: 3. In the Name field, enter the name of the organization. 4. In the Type field, select the type of the organization, such as Company, Department, or Branch. 5. Specify the parent organization to which the newly created organization will belong. To do so: a. Click the search icon next to the Parent Organization field. The Search: Organizations dialog box is displayed, as shown in Figure 13–6 : Table 13–2 Fields in the Create Organization Page Field Description Name The name of the organization Type The type of the organization, either Company, Department, or Branch Parent Organization The organization to which the newly created organization will belong Managing Organizations 13-7 Figure 13–6 The Search: Organizations Dialog Box

b. Select any one of the following options:

– All: On selecting this option, the search is performed with the AND condition. This means that the search operation is successful only when all the search criteria specified are matched. – Any: On selecting this option, the search is performed with the OR condition. This means that the search operation is successful when any search criterion specified is matched.

c. In the Organization Name field, enter the organization name that you want to

search. You can use wildcard characters in your search criteria. Select a search condition in the list adjacent to the Organization Name field. The search conditions include Equals or Begins With.

d. In the Organization Customer Type field, enter the organization type of the

parent organization. You can use wildcard characters in your search criteria. Select a search condition in the list adjacent to the Organization Customer Type field.

e. Click Search. The organizations that match the search criteria you specified

are displayed in the search results table.

f. From the search results table, select the organization that you want to specify

as the parent organization.

g. Click Finish. The selected organization is added as the parent organization.

6. Click Save to create the organization.

13.2.4 Viewing and Modifying Organizations

The view organization operation allows you to view detailed organization profile information in the User Details page. You can view this page only if you are authorized to view the organization profile as determined by the authorization policy on the View Organization Detail privilege. If you have the authorization to modify the organization, then you can also modify the organization by using this page. Note: The organization details page for the organization entity is auto-generated by the system based on configuration and fine-grained authorization. In Oracle Identity Manager, there is no mechanism to override the system-generated page with a custom-defined page. 13-8 Oracle Fusion Middleware Users Guide for Oracle Identity Manager To open the details of an organization, perform any one of the following: ■ In the left pane of Oracle Identity Manager Administration, click the Browse tab. Under Organization, select the organization whose details you want to display. From the Actions menu, select Open. Alternatively, click the Open icon on the toolbar. ■ Perform a simple search for the organization whose details you want to display. From the search result, select the organization. From the Actions menu, select Open . Alternatively, click the Open icon on the toolbar. ■ Perform an advanced search for the organization whose details you want to display. From the advanced search result, select the organization, and from the Actions menu, select Update Org. Alternatively, click Open on the toolbar. The organization details page is displayed, as shown in Figure 13–7 : Figure 13–7 The Organization Details Page You can perform administrative organization modifications in the organization details page. The modification is divided across the different sections of the organization details page, which means that modifications done in each section are independent of each other and must be saved individually. The modification for each section is described in the following sections: ■ Modifying Organization Attributes ■ Viewing Child Organizations ■ Viewing User Information ■ Modifying Resources

13.2.4.1 Modifying Organization Attributes

The Attributes tab, as shown in Figure 13–7 , of the organization details page displays attributes of the organization. If you are authorized to modify the organization profile as determined by authorization policy on the Modify Organization Profile privilege, Note: You must have organization create permission to update or delete organizations. Managing Organizations 13-9 then the organization details page opens in editable mode and you can modify organization information. You can modify the values for the attributes, and then click Save to save the changes. Whether or not the logged-in user is allowed to modify the organization is controlled by authorization policies. If you are not allowed to modify the organization, then the organization details page is displayed in read-only mode with no editable fields. See Organization Management Authorization on page 13-14 for information about authorization of the organization management feature.

13.2.4.2 Viewing Child Organizations

The Hierarchy tab is a read-only tab that displays a list of child organizations that the selected organization has. For each child organization in the list, the following are displayed: ■ Organization name ■ Type ■ Status From the Hierarchy tab, you can open the details of a child organization by selecting the organization, and selecting Open from the Actions menu. Alternatively, you can click Open on the toolbar, or simply click the name of the organization. To modify a child organization, click the child organization name that you want to modify. The organization details page for the selected organization is displayed, by using which you can modify the details of that organization.

13.2.4.3 Viewing User Information

The Members tab is a read-only tab that displays a list of users in the selected organization. For each user in the list, the following are displayed: ■ User Name ■ First Name ■ Last Name ■ Manager Name From the Members tab, you can open the details of a user by selecting the user, and selecting Open from the Actions menu. Alternatively, you can click Open on the toolbar, or simply click the name of the user.

13.2.4.4 Modifying Resources

The Resources tab displays the permitted resources for the selected organization. You can select one or multiple resources in the list, and then perform the following: ■ Provisioning Resources ■ Revoking Resources Note: The Status attribute in the organization details page is read-only. Tip: You can add or remove users to and from organizations by using the Attributes tab of the user details page. For more information, see The Attributes Tab on page 11-38. 13-10 Oracle Fusion Middleware Users Guide for Oracle Identity Manager

13.2.4.4.1 Provisioning Resources To provision resources to the organization:

1. From the Actions menu, select Provision. Alternatively, click Provision on the

toolbar. This brings up a wizard Step 1: Select a Resource. 2. Search for the resource that you want to provision. Select the resource and click Continue . 3. In the Step 2: Verify Resource Selection page, the resource that you selected for adding to the organization is displayed. Verify the information and click Continue . Provisioning the selected resource to the organization starts. 4. Close the Provision Resource to Organization wizard. The resource is added to the Hierarchy tab.

13.2.4.4.2 Revoking Resources To revoke a resource:

1. Select the resource that you want to remove.

2. From the Actions list, select Revoke. Alternatively, click Revoke on the toolbar. A

message is displayed asking for confirmation.

3. Click OK to confirm.

13.2.5 Disabling and Enabling Organizations

To disable an organization with enabled state:

1. In the organization details page, click Disable Organization on the top of the

page. A message is displayed asking for confirmation. Alternatively, in the simple search result for organizations, select the organization, and from the Actions menu, select Disable.

2. Click OK to confirm. A message is displayed stating that the organization is

successfully disabled.

3. Click OK.

To enable an organization with disabled state:

1. In the organization details page, click Enable Organization on the top of the page.

Alternatively, in the simple search result for organizations, select the organization, and from the Actions menu, select Enable. A message is displayed asking for confirmation.

2. Click OK to confirm. A message is displayed stating that the organization is

successfully enabled. Tip: If the provisioned resource is not displayed in the Hierarchy tab, then click Refresh on the toolbar. Note: ■ You cannot disable organizations with child orgs or users. You can force delete it only by setting the system property ORG.DISABLEDELETEACTIONENABLED to true. Once you set the property, the users and sub orgs will be deleted while deleting the parent org. ■ You can disable an organization only if you have the Write permission for that organization.