Granting Access to the IAM Shop with Management Roles
EmpowerID employs Management Roles to control access to the IAM Shop. Users must be assigned to relevant roles to gain access to this feature. These Management Roles are classified by their specific functions within EmpowerID and include:
- UI-Prefixed Roles: Management Roles that start with 'UI' provide users access to certain UI elements within the EmpowerID Web interface. This allows for a tailored user experience, giving access only to the necessary interface components.
- VIS-Prefixed Roles: Roles prefixed with 'VIS' grant users visibility rights over specific objects within EmpowerID. This ensures that users can see only the objects relevant to their role, making for an efficient and clutter-free workspace.
- ACT-Prefixed Roles: Management Roles beginning with 'ACT' allow users to manage certain objects within EmpowerID. This gives users the necessary permissions to perform specific actions on selected objects, aligning with their job responsibilities.
To shop for eligible resources in the IAM Shop, users must be assigned one or more of the applicable Management Roles below, depending on the needed scope.
Expand each section below to view the UI controls, pages, web services, and workflows included in that role.
UI-IT-Shop-MS-Application
- Role Type: Feature Set (UI)
- Grants Access To: Shop for Applications in the IAM Shop microservice app.
- User Interface Controls
- Pages and Reports
- Workflows
Grants Viewer access to:
- Applications Grid Control (IT Shop)
- ITShop Parsed Html More information text Control
- ITShop Show Only Azure Applications Control
- Create Azure Application Workflow Control (IT Shop)
- ITShop-PreApprovedApplications-Control
- ITShop-TimeConstrainedApplications-Control
Grants Viewer access to:
- Application Roles Page (IT Shop)
Grants Initiator access to:
- CreateAzureApplication
UI-IT-Shop-MS-Application-Role
- Role Type: Feature Set (UI)
- Grants Access To: Shop for Application Roles (Groups) in the IAM Shop microservice app.
- User Interface Controls
- Pages and Reports
- Web Services
Grants Viewer access to:
- Target System Control (IT Shop)
- TCodes Grid Control (IT Shop)
- Manage Access Business Request Attribute Control (IT Shop)
- Application Roles Business Functions Control (IT Shop)
- Application Processes Control (IT Shop)
- Suggested Application Roles Control (IT Shop)
- Application Roles Account Store Attribute Control (IT Shop)
- Application Roles Resource System Attribute Control (IT Shop)
- Application Roles Applications Control (IT Shop)
- Application Roles Owners Attribute Control (IT Shop)
- Application Roles Advanced Search Control (IT Shop)
- Application Roles High Level Classification Attribute Control (IT Shop)
- Application Roles Name Attribute Control (IT Shop)
- Application Roles TCode Control (IT Shop)
- Pre-Approved Application Roles Control (IT Shop)
Grants Viewer access to:
- Application Roles Page (IT Shop)
Grants Executor access to:
- GroupsAPI.GetAssignedAppRolesByPersonGUID
- GroupsAPI.GetUser
- GroupsAPI.OwnersByAppRoleId
- GroupsAPI.GetAnonymousInfo
- GroupsAPI.GetAssignedMembershipByOrgRoleOrgZoneID
- GroupsAPI.GetGroups
- GroupsAPI
- GroupsAPI.GetTargetSystemFilterdata
- GroupsAPI.GetSuggestedAppRolesByOrgRoleIdOrgZoneId
- GroupsAPI.GetSingleOrgRole
- GroupsAPI.ApproversByAppRoleId
- GroupsAPI.CheckAssignmentStatus
- GroupsAPI.GetOwnersAndApprovers
- GroupsAPI.GetUserGroups
UI-IT-Shop-MS-Azure-Admin-Role
- Role Type: Feature Set (UI)
- Grants Access To: Shop for Azure Admin Directory Roles in the IAM Shop microservice app.
- User Interface Controls
- Pages and Reports
- Web Services
Grants Viewer access to:
- Azure Admin Roles Role Types Control (IT Shop)
- Manage Access Business Request Attribute Control (IT Shop)
- Azure Admin Roles Resource System Attribute Control (IT Shop)
- Azure Admin Roles Role Type Attribute Control (IT Shop)
- Azure Admin Roles Advanced Search Control (IT Shop)
- Azure Admin Roles Global Functions Control (ITShop)
- Azure Admin Roles Tenants Control (IT Shop)
Grants Viewer access to:
- Azure Admin Roles Page (IT Shop)
Grants Executor access to:
- AzureRolesAPI.CheckAssignmentStatus
- AzureRolesAPI.GetRoleTypes
- AzureRolesAPI
- AzureRolesAPI.GetAdTree
- AzureRolesAPI.GetSingleAzureAdminRole
- AzureRolesAPI.GetAllAssigned
- AzureRolesAPI.GetAzureAdminRoles
UI-IT-Shop-MS-Azure-License
- Role Type: Feature Set (UI)
- Grants Access To: Shop for Azure Licenses in the IAM Shop microservice app.
- User Interface Controls
- Pages and Reports
- Web Services
Grants Viewer access to:
- Azure Licenses Tenant Subscription Attribute Control (IT Shop)
- Azure Licenses Resource System Attribute Control (IT Shop)
- Azure Licenses Name Attribute Control (IT Shop)
- Azure License Pool Control (IT Shop)
- Manage Access Business Request Attribute Control (IT Shop)
- Azure Licenses License Pool Attribute Control (IT Shop)
- Azure Subscription Control (IT Shop)
- Azure Licenses Advanced Search Control (IT Shop)
- Azure Licenses Licensed Assignee Attribute Control (IT Shop)
- Azure Licenses Tenants Control (IT Shop)
Grants Viewer access to:
- Azure Licenses Page (IT Shop)
Grants Executor access to:
- AzureLicenseBundleAPI.GetTenantSubscriptionServices
- AzureLicenseBundleAPI
- AzureLicenseBundleAPI.GetAllEligibleLicenseBundlesByAssigneeId
- AzureLicenseBundleAPI.GetSinglee
- AzureLicenseBundleAPI.GetAllAzLocalServiceBundles
- AzureLicenseBundleAPI.GetAllAssignedLicenseBundlesByAssigneeId
- AzureLicenseBundleAPI.GetAllAzLicensePool
- AzureLicenseBundleAPI.GetAllAzureAdScimResourceSystems
- AzureLicenseBundleAPI.CheckAssignmentStatus
UI-IT-Shop-MS-Azure-RBAC-Role
- Role Type: Feature Set (UI)
- Grants Access To: Shop for Azure RBAC Roles in the IAM Shop microservice app.
- User Interface Controls
- Pages and Reports
- Web Services
Grants Viewer access to:
- Azure Rbac Roles Global Functions Control (ITShop)
- Azure Rbac Roles Role Types Control (IT Shop)
Grants Viewer access to:
- Azure Rbac Roles Page (ITShop)
Grants Executor access to:
- AzureRolesAPI.GetRoleTypes
- AzureRolesAPI.CheckAssignmentStatus
- AzureRolesAPI.GetAzureRbacRoles
- AzureRolesAPI.GetAdTree
- AzureRolesAPI.GetAllAssigned
- AzureRolesAPI
- AzureRolesAPI.GetSingleAzureRole
UI-IT-Shop-MS-Business-Role
- Role Type: Feature Set (UI)
- Grants Access To: Shop for Business Roles in the IAM Shop microservice app.
- User Interface Controls
- Pages and Reports
- Web Services
Grants Viewer access to:
- Azure Rbac Roles Global Functions Control (ITShop)
- Azure Rbac Roles Role Types Control (IT Shop)
Grants Viewer access to:
- Azure Rbac Roles Page (ITShop)
Grants Executor access to:
- AzureRolesAPI.GetRoleTypes
- AzureRolesAPI.CheckAssignmentStatus
- AzureRolesAPI.GetAzureRbacRoles
- AzureRolesAPI.GetAdTree
- AzureRolesAPI.GetAllAssigned
- AzureRolesAPI
- AzureRolesAPI.GetSingleAzureRole
UI-IT-Shop-MS-Common
- Role Type: Feature Set (UI)
- Grants Access To: Shared UI and API features required by the IAM Shop microservice app.
- Applications
- User Interface Controls
- Web Services
Grants Viewer access to:
- IT Shop Microservice App
Grants Viewer access to:
- Manage Access Workflow Id Attribute Control (IT Shop)
- Resource's Access Request Policy Control (IT Shop)
- ITShop-ShowManageAccessFiltersBar-Control
- Reassign Cart Approver Control (IT Shop)
- Shop For Target Person Control (IT Shop)
- ITShop Workflow Tab Control
- Simple Text Search Control (IT Shop)
- Manage Access View Pending Access Control (IT Shop)
- Shop By Reference Person Control (IT Shop)
- Show Cart Approver Control (IT Shop)
- Manage Access Business Request Attribute Control (IT Shop)
- Show Guided Shop for first time login (IT Shop)
- Cart Due Date Control (IT Shop)
Grants Executor access to:
- MscPerson.GetSearch
- CartSubmissionAPI.GetAnonymousInfo
- CartSubmissionAPI.SubmitCart
- CartSubmissionAPI.DefaultApprover
- MscPerson.GetPersonByGUID
- MscProtectedApplication.GetTargetSystemFilterData
- CartSubmissionAPI.GetUserGroups
- MscPerson.GetPhoto
- LocalizationAPI
- MscLocalization.AvailableLanguages
- CartSubmissionAPI.BusinessRequestTypes
- CartSubmissionAPI.ProcessAzureAdminRoles
- CartSubmissionAPI.ProcessGroups
- CartSubmissionAPI.GetUser
- CartSubmissionAPI.ProcessOrgRoles
- CartSubmissionAPI.SuggestedApprovers
- MscLocalization.GetByResourceSet
- CartSubmissionAPI
- MscGlobalConfig.GetConfigSetting
- CartSubmissionAPI.ProcessLicenseBundles
- CartSubmissionAPI.ProcessManagementRoles
- CartSubmissionAPI.GetCartItemResults
- MscProtectedApplication.GetChildren
- LocalizationAPI.CountryHelpText
- MscProtectedApplication.AllowedSsoApplications
UI-IT-Shop-MS-Computer
- Role Type: Feature Set (UI)
- Grants Access To: Shop for access to servers in the IAM Shop microservice app.
- User Interface Controls
- Pages and Reports
- Web Services
Grants Viewer access to:
- Computers Advanced Search Control (IT Shop)
- Target System Control (IT Shop)
- Manage Access Business Request Attribute Control (IT Shop)
Grants Viewer access to:
- Computers Page (IT Shop)
Grants Executor access to:
- ComputersAPI.GetComputers
- ComputersAPI.GetTargetSystemFilterData
- ComputersAPI.GetComputer
UI-IT-Shop-MS-Mailbox
- Role Type: Feature Set (UI)
- Grants Access To: Shop for Office 365 Mailboxes in the IAM Shop microservice app.
- User Interface Controls
- Pages and Reports
- Web Services
Grants Viewer access to:
- Mailboxes Advanced Search Control (IT Shop)
- Target System Control (IT Shop)
- Manage Access Business Request Attribute Control (IT Shop)
Grants Viewer access to:
- Mailboxes Page (IT Shop)
Grants Executor access to:
- MailBoxesAPI.GetAllMailBoxes
- MailBoxesAPI.GetAllMailBoxTypes
- MailBoxesAPI.GetSingleMailBox
UI-IT-Shop-MS-Full-Access
- Role Type: Feature Set (UI)
- Grants Access To: All item types and UI features in the IAM Shop microservice app.
- Applications
- User Interface Controls
- Pages and Reports
- Web Services
- Workflows
Grants Viewer access to:
- EmpowerID Web
- IT Shop Microservice App
Grants Viewer access to all major controls used across the IAM Shop including (not exhaustive):
- Manage Access View Pending Access Control (IT Shop)
- Shop For Target Person Control (IT Shop)
- Simple Text Search Control (IT Shop)
- Azure Admin Roles Resource System Attribute Control (IT Shop)
- Application Roles Resource System Attribute Control (IT Shop)
- ... (multiple additional controls from each domain)
Grants Viewer access to:
- Business Roles Page (IT Shop)
- Azure Licenses Page (IT Shop)
- Azure Rbac Roles Page (IT Shop)
- Application Roles Page (IT Shop)
- Azure Admin Roles Page (IT Shop)
- Management Roles Page (IT Shop)
Grants Executor access to:
- CartSubmissionAPI.SubmitCart
- AllRbacObjects
Grants Initiator access to:
- UpdatePersonManagementRoles
- UpdatePersonBusinessRoles
- UpdatePersonDirectAssignment
UI-IT-Shop-MS-Management-Role
- Role Type: Feature Set (UI)
- Grants Access To: Shop for EmpowerID Management Roles in the IAM Shop microservice app.
- User Interface Controls
- Pages and Reports
- Web Services
- Workflows
Grants Viewer access to:
- Management Roles Advanced Search Control (IT Shop)
- Target System Control (IT Shop)
- Manage Access Business Request Attribute Control (IT Shop)
Grants Viewer access to:
- Management Roles Page (IT Shop)
Grants Executor access to:
- ManagementRolesAPI.GetManagementRoles
- ManagementRolesAPI.GetSingleManagementRole
- ManagementRolesAPI.GetAllAssigned
- ManagementRolesAPI.CheckAssignmentStatus
Grants Initiator access to:
- UpdatePersonManagementRoles
UI-IT-Shop-MS-Risk
- Role Type: Feature Set (UI)
- Grants Access To: View and interact with Risks in the IAM Shop microservice app.
- User Interface Controls
- Web Services
Grants Viewer access to:
- Risk Advanced Search Control (IT Shop)
- Target System Control (IT Shop)
- Manage Access Business Request Attribute Control (IT Shop)
Grants Executor access to:
- RiskAPI.GetRisks
- RiskAPI.GetRiskTypes
- RiskAPI.GetSingleRisk
UI-IT-Shop-MS-Shared-Credential
- Role Type: Feature Set (UI)
- Grants Access To: Shop for Shared Credentials in the IAM Shop microservice app.
- User Interface Controls
- Pages and Reports
- Web Services
Grants Viewer access to:
- Credentials Advanced Search Control (IT Shop)
- Target System Control (IT Shop)
- Manage Access Business Request Attribute Control (IT Shop)
Grants Viewer access to:
- Shared Credentials Page (IT Shop)
Grants Executor access to:
- ExternalCredentialsAPI.GetAllExternalCredentials
- ExternalCredentialsAPI.GetSingleExternalCredential
- ExternalCredentialsAPI.ValidateMasterPassword
- ExternalCredentialsAPI.CheckInCredential
- ExternalCredentialsAPI.CheckOutCredential