cancel
Showing results for 
Search instead for 
Did you mean: 

IdM UI Task - Help

Matt_Marples
Participant
0 Kudos

Has anyone used the 'Default search filter' option for a UI task and if so, how could it be used?

Accepted Solutions (1)

Accepted Solutions (1)

Steffi_Warnecke
Active Contributor
0 Kudos

Hello Matthew,

that works pretty nicely, if you use it like this:

Then only the roles and their hierarchy (privileges and roles) are shown. But the user can change the filter any time to search for other things.

If you don't want to give the user that choice, then you just enable the check box "Read only search filter", too, and the user has to live with that default filter and can't change it.

But like I said, that's all explained, if you click on "Help" in your screenshot there. The IDM help is pretty good.

Regards,

Steffi.

Matt_Marples
Participant
0 Kudos

Many Thanks, much appreciated

jaisuryan
Active Contributor
0 Kudos

Hi Steffi,

I have a doubt here. I dint give ROLE* in default search filter and just ticked Include direct assignments only

But that did not work. As per help file, my understanding was that indirect assignments (meaning the privileges in the role) wouldn't be displayed.

Please help me in understanding the use of Include direct assignments only check box

Kind regards,

Jai

Former Member
0 Kudos

Hello Jai,

If Include direct assignments only  is checked then it shows only directly assigned prviileges/roles.

Radio button would checked with '.' (Dot), so, if privileges are shown then you would notice this and thats means those privileges are directly assigned.

Regards,

Pradeep

Steffi_Warnecke
Active Contributor
0 Kudos

Hmm, but the help says:


If a displayed role has inherited assignments, you will still be able to browse

the hierarchy below the role.

With the filter you set, which content is displayes, when you call the UI mask. And I would understand this option that way, that you will only see direct assignments on the top level, but if a directly assigned role has a hierarchy, it will be displayed and you can see the through the direct role indirectly to the user assigned roles and privileges.

And when I test it, this is exactly what I see for this attribute. ^^

jaisuryan
Active Contributor
0 Kudos

Hi Pradeep,


That was my expectation as well. But it displayed the direct role, and privileges (without 'dot') assigned to that role.

Kind regards,

Jai

Steffi_Warnecke
Active Contributor
0 Kudos

As is designed according to the help. That's the way it is supposed to work. ^^

ivan_petrov
Active Participant
0 Kudos

Hi Jai,

The filter "direct assignments only" is working as it should. You can have direct assignments to the person and you can see only them with this filter on, but still you are able to browse business roles assignments in order to be able to do that, this filter you set should not work for browsing business roles, otherwise you won't see any privileges or other business roles, because they are indirectly attached to the business role you are browsing. So this is the reason why the filter works only for first level of assignments.

Best regards,

Ivan

Answers (2)

Answers (2)

Matt_Marples
Participant
0 Kudos

Hi All,

It didn't work for me either. I set the option both at the attribute level and in the UI task that held the attribute. Any other ideads?

jaisuryan
Active Contributor
0 Kudos

Hi Matthew,

The initial solution Steffi suggested worked sweet for me. When i opened the UI task for displaying users, I was able to see only the roles assigned to the user.

Would be good if you post the UI task (Attributes tab) and Attribute.

Kind regards,

Jai

Matt_Marples
Participant
0 Kudos

Hi Jai,

The setting for both the attribute and UI attribute are display below:

Attribute

UI Attribute:

When I open a Identity through the change 'UI Task' I still see the all of the privileges as well as the role with the corresponding privileges.

I only want to see the roles and their corresponding privileges as per the latter screenshot?

jaisuryan
Active Contributor
0 Kudos

Hi Matthew,

You have roles within the roles(business roles). ROLE:* filter shows only the roles excluding groups etc.. Could you please try again with "Include direct assignments only" checked?

Please post the results again. Thanks.

Kind regards,

Jai

Matt_Marples
Participant
0 Kudos

Hi Jai, will this remove anything that has been provisioned through dynamic groups or still waiting for Line Manager Approval?

jaisuryan
Active Contributor
0 Kudos

Hi Matthew,

You have set status filter as 'All' so I would expect it to display all direct assignments of role regardless of the status.

Kind regards,

Jai

Matt_Marples
Participant
0 Kudos

Hi Jai, this work fine for direct assignment of roles/privileges and any inherited privileges from the role, but if a role has been provisioned through dynamic groups (indirect) then it isn't displayed.

If i was to type in Role* in the UI task on the search option it displays the roles (whether direct/indrect) and their inherit privileges. This is what I am really looking for.

Steffi_Warnecke
Active Contributor
0 Kudos

But that is through just giving "ROLE:*" for the default filter for MX_ASSIGNMENT. It works like that for me. I see all the roles and their hierarchy, but no privileges on the first level.

The first screenshot looks like you look at MXREF_MX_PRIVILEGE not MX_ASSIGNMENT.

Matt_Marples
Participant
0 Kudos

Hi Steffi, we are definitely using MSASSIGNMENT and I've tried put in the "ROLE:*" and ROLE:*. None of them have provided me with the view I want. Could it be something to do with our java version as it states in the help file?

Steffi_Warnecke
Active Contributor
0 Kudos

That is the portal version. What is your portal version, where you have included the IDM UI?

Did you scroll down the MX_ASSIGNMENT-attribute to get the first screenshot of the UI? Can you take a screenshot of the whole mask, please?

Matt_Marples
Participant
0 Kudos

Steffu, we are on 7.01 Portal. Not sure what you mean by your second point. Both screenshot are taken from the top of the list of privileges/roles and then a  screenshot further down. Please clairify

Steffi_Warnecke
Active Contributor
0 Kudos

I meant, a screenshot of the whole UI mask where the attribute is used, not just single portions of it.

But since you are on Portal 7.01, I think you found the reason it's not working for you: That option is ignored for your version. 😕

Matt_Marples
Participant
0 Kudos

Hi Steffi, would it still be the same if I'm not accessing the IdM UI through our Portal?

Steffi_Warnecke
Active Contributor
0 Kudos

Hello Matthew,

yes, we have that in use for some UI masks. But I think, it is pretty self-explanatory and the help for it explains it well, too.

What exactly is confusing for you there?

Regards,

Steffi.

Matt_Marples
Participant
0 Kudos

Steffi,

I didn't look at any help docs for this as I wasn't aware there was any. Current our IdM system shows all the roles and privilges asssigned to users which can be quite busy. I was hoping that I could use option to filter out the priivileges and only show the role. The user then can expand the role if they want to view privileges and its status?