Sun Identity Manager 8.1 Business Administrator's Guide

Delegating Service Provider User Admin Roles

By default, Service Provider Users can assign (or delegate) Service Provider User Admin Roles assigned to them to other Service Provider Users in their scope of control.

In fact, any Identity Manager User with capabilities to edit Service Provider Users can assign the Service Provider User Admin Roles assigned to them to the service provider users in their scope of control.

A Service Provider User Admin Role can also include a list of Assigners who can assign the Admin Role regardless of scope of control. These direct assignments can ensure that at least one known user account can assign the Admin Role.