Add Role

Initiates a request to the Roles Based Provisioning Module (RBPM) to assign the specified role (in the Role DN field) to the specified user (in the Authorized User DN field). This field is only available if the Identity Manager server version is set to 3.6 or later.

Fields

Role DN

Specify the name of the role to assign, in LDAP format. Supports variable expansion. For more information, see Section 3.6, Variable Selector.

User Application URL

Specify the URL of the User Application server hosting the Roles Based Provisioning module. Supports variable expansion. For more information, see Section 3.6, Variable Selector.

Authorized User DN

Specify the name of the user authorized to request the role assignment, in LDAP format. Supports variable expansion. For more information, see Section 3.6, Variable Selector.

Password

Specify the authorized user password. You can enter a clear text password (not recommended) or use the Argument Builder to specify a Named Password.

Object

Select the target object type. This object can be the current object, or can be specified by a DN or an association.

Strings

(Optional) Specify additional argument strings for the Role assignment request. You can enter the strings manually, or select the Edit the Strings icon Edit the Strings icon to open the Named String Builder and specify the strings. For more information about the Named String Builder, see Section 4.9, Named String Builder.

The Add Role action supports the following string arguments:

String Name

Description

description

A description of the reason for the request used for auditing and (if necessary) approval purposes.

Default: Request generated by policy.

effective-time

The time (in CTIME format) the role assignment should become effective.

Default: now

expiration-time

The time (in CTIME format) the role assignment automatically expires.

Default: never

sod-justification

A justification for requesting an exception for any Separation of Duty violations this assignment will trigger.

Default: No exception will be requested and the request will fail if it causes a violation.

NOTE:By default, the Named String Builder does not display this string. However, you can manually add it to the string list.

Example

Add source attribute value