Creating Entitlements
4
17
no
vd
ocx
(e
n)
13
Ma
y 20
09
4
Creating Entitlements
Because entitlements represent resources in a connected system, each entitlement must be created on
the driver associated with the connected system. For example, to create an entitlement for an Active
Directory User Account, you would create it on the Active Directory driver that connects to the
directory where you want the account created.
The following sections provide instructions for creating entitlements in Designer and iManager.
Although you can use either tool to create entitlements, we strongly recommend that you use
Designer. Designer includes an Entitlement Wizard that creates the entitlement XML from the
information you provide in the wizard. iManager does not include this wizard; instead, you must
write the XML required for the entitlement.
Section 4.1, “Sample Entitlements for the Active Directory Driver,” on page 17
Section 4.2, “Creating Entitlements in Designer,” on page 17
Section 4.3, “Creating Entitlements in iManager,” on page 24
4.1 Sample Entitlements for the Active Directory
Driver
By default, the Active Directory driver includes the entitlements listed below. You can use these
entitlements as examples of the types of entitlements you might want to create for other drivers.
User Account Entitlement:
Grants or revokes an account in Active Directory for the user.
When the account is granted, the user is given an enabled logon account. When the account is
revoked, the logon account is either disabled or deleted, depending on how the driver is
configured.
Group Membership Entitlement:
Grants or revokes membership in a group in Active
Directory. When membership is revoked, the user is removed from the group. The group
membership entitlement is not enforced on the Publisher channel; if a user is added to a
controlled group in Active Directory by some external tool, the user is not removed by the
driver. Further, if the entitlement is removed from the user object instead of being simply
revoked, the Active Directory driver takes no action.
Exchange Mailbox Entitlement:
Grants or revokes an Exchange mailbox for the user in
Microsoft Exchange.
4.2 Creating Entitlements in Designer
Designer is the recommended tool for creating entitlements.
Designer provides an Entitlement Wizard that steps you through the creation of entitlements. The
wizard creates the entitlement XML from the information you provide. In iManager, you must
manually create the entitlement XML (see
Section 4.3, “Creating Entitlements in iManager,” on
page 24
)
1
In the Modeler view for your Designer project, right-click the driver icon , then click
New
>
Entitlement
to launch the Entitlement Wizard.
2
Fill in the following fields:
Summary of Contents for IDENTITY MANAGER 3.6.1 - ENTITLEMENTS
Page 4: ...4 Identity Manager 3 6 1 Entitlements Guide novdocx en 13 May 2009...
Page 6: ...6 Identity Manager 3 6 1 Entitlements Guide novdocx en 13 May 2009...
Page 8: ...8 Identity Manager 3 6 1 Entitlements Guide novdocx en 13 May 2009...
Page 12: ...12 Identity Manager 3 6 1 Entitlements Guide novdocx en 13 May 2009...
Page 26: ...26 Identity Manager 3 6 1 Entitlements Guide novdocx en 13 May 2009...
Page 44: ...44 Identity Manager 3 6 1 Entitlements Guide novdocx en 13 May 2009...