Idea ID 2779834
IG: Deprovisioning of granted Permissions by Business Role modification
Status:
Waiting for Votes
Submitted by
KScherbach
on
2018-02-09
09:03

IG 3.0 seems not to provide a mechanism that causes deprovisioning of a granted permission that is deleted from a Business Role. There must be a way to achieve this. Sample:
- Business Role BR authorizes Permission P1 and P2 and is configured for automatic provisioning
- P1 and P2 are configured for automatic grant and revoke
- all BR members have been provisioned with P1 and P2
- now P2 shall be removed from BR
- whatever you do today (delete P2, set P2 validity end date) will not deprovision P2 from the BR
members
Removing a Permission or Role or nested Business Role from a Business Role should cause appropriate deprovisioning actions.
- Business Role BR authorizes Permission P1 and P2 and is configured for automatic provisioning
- P1 and P2 are configured for automatic grant and revoke
- all BR members have been provisioned with P1 and P2
- now P2 shall be removed from BR
- whatever you do today (delete P2, set P2 validity end date) will not deprovision P2 from the BR
members
Removing a Permission or Role or nested Business Role from a Business Role should cause appropriate deprovisioning actions.
Labels
- Labels:
-
Other
2 Comments
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.