7.3 Reflecting Permissions and Assignments from Applications Not Connected to Identity Manager

Identity Governance can collect account and permission data from application sources that do not have role and resource objects in Identity Manager. The Identity Governance driver serves as the proxy for the application sources. For more information, see Section 7.1.1, Reflecting Application Permissions in Identity Manager.

NOTE:The driver needs both a system account and a workflow in the User Application to create resources. For more information, see “Installing and Configuring the Identity Governance Driver” in the NetIQ Identity Manager Driver for Access Review Installation and Configuration Guide.

  1. Log in to Identity Governance as a Global Administrator.

  2. Add the Identity Manager information to Identity Governance.

    1. Select Configuration, then expand the Identity Manager system connection information section.

    2. Provide the Identity Manager URL. For example: https//myserver:8543/IDMProv.

    3. Click Load Certificate and click Load to add the Base64 encoded certificate for the server.

    4. Add the administrator user name and password for your Identity Manager system. For example, cn=uadmin,ou=sa,o=data.

    5. Select Test Connection. Ensure that you have a valid connection before proceeding.

  3. Under Catalog, select Applications.

  4. Select an application that you want to integrate with Identity Manager.

  5. Select the icon for Edit application.

  6. Under Identity Manager Synchronization, select Reflect permissions and assignments as resources in Identity Manager.

  7. Specify the provisioning workflow that you want Identity Manager to use.

  8. For Identity Manager Resource Owner, specify the user account in Identity Manager that can grant permissions for the application. For example, the application owner.

    In Identity Governance, the name for this user is the concatenation of the account GivenName and Surname attributes. For more information about this account, see “Creating an Identity Manager Provisioning Service Account for the Driver” in the NetIQ Identity Manager Driver for Access Review Installation and Configuration Guide.

  9. For each application, repeat Step 4 through Step 8.