Skip Headers
Oracle® Identity Manager Reference
Release 9.1.0

Part Number E10375-02
Go to Documentation Home
Home
Go to Book List
Book List
Go to Table of Contents
Contents
Go to Index
Index
Go to Feedback page
Contact Us

Go to previous page
Previous
Go to next page
Next
View PDF

1 The Administrative and User Console

Oracle Identity Manager client tier consists of two interfaces, the Administrative and User Console and the Design Console. Using the Administrative and User Console, you can create requests for resources and approve the provisioning of resources of the users that you manage. Users can search for, edit, and delete account information in the Oracle Identity Manager database by using the Administrative and User Console.

This chapter contains the following topics:

Components of the Administrative and User Console

The left navigation pane of the Administrative and User Console lists the menu items that enable you to perform various administrative tasks, such as managing Oracle Identity Manager accounts and managing resources. The menu items are grouped together according to functionality; for example, the menu items for creating and managing users are grouped under one head. Figure 1-1 shows the Welcome screen of the Administrative and User Console.

Figure 1-1 The Welcome Screen of the Administrative and User Console

Description of Figure 1-1 follows
Description of "Figure 1-1 The Welcome Screen of the Administrative and User Console"

This section describes the functionalities offered by the Administrative and User Console that are grouped under the following top-level menu items:

My Account

In the My Account section, you can access and manage your Oracle Identity Manager account by using the following menu items:

My Resources

In the My Resources section, you can view resources that have been provisioned to you and request access to resources for yourself and others by using the following menu items:

Requests

In the Requests section, you can create and track requests for resources that you have requested for users and organizations by using the following menu items:

To-Do List

A To-Do list is a list of tasks within a process. The processes for approving requests and their associated resources and making them available for provisioning consist of tasks, which can be performed by using the following menu items:

Users

In the Users section, you can create and manage user records, for example, Oracle Identity Manager accounts, that your employees require. You can create and manage user records by using the following menu items:

Organizations

In the Organizations section, you can create and manage information pertaining to your organization by using the following menu items:

User Groups

You use user groups to create and manage records of collections of users to whom you can assign some common functionality, such as access rights, roles, or permissions. You can modify the permissions associated with these user groups, and you can create additional user groups by using the following menu items:

Access Policies

In the Access Policies section, you can create and use access policies for users and resources in Oracle Identity Manager. You define an access policy for provisioning resources to user groups and users. You can create and use access policies by using the following menu items:

Resource Management

The Resource Management feature lets you manage resource objects for an organization or an individual user by using the menu items:

Deployment Management

The Deployment Manager is a tool used for exporting and importing Oracle Identity Manager configurations. The Deployment Manager enables you to export the objects that constitutes your Oracle Identity Manager configuration. You use the Deployment Manager to exchange Oracle Identity Manager items between environments. Usually, you use the Deployment Manager to migrate a configuration from one deployment to another, for example, from a test to a production deployment, or to create a backup of your system. The Deployment Management section provides the following menu items:

Reports

Based on whether you access current operational data or historical data, the reports you can generate by using Oracle Identity Manager are divided into Operational Reports and Historical Reports. These reports describe the resources available to users.

Operational Reports

Operational reports can be used by administrators and auditors for operational and compliance purposes. Operational reports are of the following types:

Historical Reports

Administrators and auditors can use historical reports for compliance and forensic auditing purposes. Historical reports are of the following types:

See Also:

The "Oracle Identity Manager Reporting" chapter in Audit Report Developer's Guide for the entire list of operational and historical reports

Generic Technology Connector

Using this menu item, you can create and manage generic technology connectors.

Attestation

In this section, you can create, manage, and view attestation tasks by using the following menu items:

Settings for Configuring Administrative and User Console Functions

This section describes the settings in the Administrative and User Console for configuring functions such as user registration and account creation. Review this section prior to deploying the Oracle Identity Manager Administrative and User Console to ensure that you have configured the product to function as intended.

This section discusses the following topics:

To customize the Oracle Identity Manager Administrative and User Console user interface, see Oracle Identity Manager Administrative and User Console Customization Guide.

Settings for Configuring User Registration Operations

Table 1-1 describes the settings for user registration operations.

Table 1-1 Settings for User Registration Operations

Function Description

To allow users to self-register in Oracle Identity Manager

Set the Is Self-Registration Allowed property in the System Configuration form to true. The System Configuration form is available in the Oracle Identity Manager Design Console.

To require users to select their verification questions and provide answers to these question when registering

Set the Does user have to provide challenge information during registration property in the System Configuration form to true. The System Configuration form is available in the Oracle Identity Manager Design Console.

To designate the number of verification questions that the user must answer

Set the Number of Questions property in the System Configuration form to the number of questions that you want users to answer. Ensure that the number of questions you supply in the Lookup.WebClient.Questions lookup definition is equal to or greater than the value of the Number of Questions property. You might need to create additional questions.

The System Configuration form is available in the Oracle Identity Manager Design Console.

To designate the list of questions that users select from when setting their verification questions and answers

Define a row on the Lookup.WebClient.Questions lookup definition for each question in the Lookup Definition form.

The Lookup Definition form is available in the Oracle Identity Manager Design Console.

To require an approval for self-registration

Define an approval task in the User Registration approval process.

To configure different workflow approvals for self-registration depending on user profile information

Define additional approval processes for the Request resource definition and create a rule of type process determination with a rule element that at least requires that the request object action is Create Entity. Associate the new rule with the approval process on the Request resource definition to enable Oracle Identity Manager to determine which process to select.

To automatically add a user to groups based on self-registration

Define rules of type general and attach them to the user group definitions to which you want users to be added on registration. This enables Oracle Identity Manager to determine which groups to add users to based on the criteria they enter on registration. The criteria in the rules must match the user-entered criteria.


Settings for Configuring Access Privileges

Table 1-2 describes the settings for configuring access privileges.

Table 1-2 Settings for Configuring Access Privileges

Function Description

To designate the pages to which all users are to be allowed access

Specify these pages on the Menu Items tab of the All Users user group.

To designate the pages to which various administrative groups are to be allowed access

Specify these pages on the Menu Items tab of the applicable administrative user groups, for example, System Administrator, AdminGroup1, and so on.


Settings for Configuring Account Creation Operations

Table 1-3 describes the settings for configuring account creation operations for administrators.

Table 1-3 Settings for Configuring Account Creation Operations for Administrators

Function Description

To allow administrators to create an Oracle Identity Manager account for other users

Ensure that the groups that these administrators belong to are added to the Administrators tab of the organizations that contain the users they are to administer.

To configure fields for administrators to supply data when creating the user account

Create these fields in the FormMetaData.xml file. See the Oracle Identity Manager Administrative and User Console Customization Guide for details.

To specify fields that are required when creating a user account

Modify these fields in the FormMetaData.xml file and set the optional property to false. See the Oracle Identity Manager Administrative and User Console Customization Guide for details.

To specify the groups of which a user is automatically made a member

Define rules of type general and attach them to the user group definitions to which you want users automatically added upon registration. This enables Oracle Identity Manager to determine which groups to add users to based on the criteria entered when their account was created. The criteria in the rules must match the entered criteria.

To designate the groups to which administrators can add users whom they administer

Ensure that the groups of which these administrators are members are added to the Administrators tab of the group definitions to which you wish to allow them to add users.


Settings for Configuring Profile Editing Operations for Users

Table 1-4 describes the settings for configuring profile editing operations for users.

Table 1-4 Settings for Configuring Profile Editing Operations for Users

Function Description

To specify that an approval is required for self-initiated Oracle Identity Manager profile updates

Define an approval task in the User Profile Edit approval process

To configure different workflow approvals for self-initiated profile updates

Define additional approval processes for the Request resource definition and create a rule of type process determination with a rule element that at least requires the request object action to be Modify Entity. Associate the rule with the approval process on the Request resource definition to enable Oracle Identity Manager to determine which process to select.

To control which fields users can edit in their own profiles

Configure the fields in the FormMetaData.xml file. See the Oracle Identity Manager Administrative and User Console Customization Guide for details.


Settings for Configuring Account Modification Operations

Table 1-5 describes the settings for configuring account modification operations for administrators.

Table 1-5 Settings for Configuring Account Modification Operations for Administrators

Function Description

To control which users can edit the profiles of other users

You must designate the forms to which members of the various administrative groups are to have access. You must also add these groups to the Administrators tab of the Organizations that contain the users they are to administer.

To control which Oracle Identity Manager system fields (for example user ID, first name, and so on) administrators can edit

You must designate which fields you want to allow administrators to edit for other users. The fields you want to make editable must be specified in the FormMetaData.xml file. See the Oracle Identity Manager Administrative and User Console Customization Guide for details.

To control which user-defined fields (for example Social Security number, local identity, and so on) administrators can edit.

You must designate which fields you want to allow administrators to edit for other users. Depending on the pages in the Administrative and User Console on which these fields are displayed, you might need to edit the FormMetaData.xml file to add attribute definitions and references for these fields. See the Oracle Identity Manager Administrative and User Console Customization Guide for details.