Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

ServiceOperationPermission Level
IdentityProviderMgtServiceaddIdP/permission/admin/manage

deleteIdP/permission/admin/manage

getAllFederatedAuthenticators/permission/admin/manage

getAllIdPs/permission/admin/login

getAllLocalClaimUris/permission/admin/manage

getAllProvisioningConnectors/permission/admin/manage

getEnabledAllIdPs/permission/admin/manage

getIdPByName/permission/admin/manage

getResidentIdP/permission/admin/manage

updateIdP/permission/admin/manage

updateResidentIdP/permission/admin/manage

Generic-Operations/permission/admin/manage



IdentityApplicationManagementServicecreateApplication/permission/admin/manage

deleteApplication/permission/admin/manage

getAllApplicationBasicInfo/permission/admin/manage

getAllIdentityProviders/permission/admin/login

getAllLocalAuthenticators/permission/admin/manage

getAllLocalClaimUris/permission/admin/manage

getAllRequestPathAuthenticators/permission/admin/manage

getApplication/permission/admin/manage

getIdentityProvider/permission/admin/manage

updateApplication/permission/admin/manage



TenantMgtAdminServiceactivateTenant/permission/protected/manage/modify/tenants

addSkeletonTenant/permission/protected/manage/monitor/tenants

addTenant/permission/protected/manage/monitor/tenants

deactivateTenant/permission/protected/manage/modify/tenants

deleteTenant/permission/protected/manage/modify/tenants

getTenant/permission/protected/manage/monitor/tenants

retrievePaginatedPartialSearchTenants/permission/protected/manage/monitor/tenants

retrievePaginatedTenants/permission/protected/manage/monitor/tenants

retrievePartialSearchTenants/permission/protected/manage/monitor/tenants

retrieveTenants/permission/protected/manage/monitor/tenants

updateTenant/permission/protected/manage/modify/tenants



UserStoreConfigAdminServiceaddUserStore/permission/admin/manage

changeUserStoreState/permission/admin/manage

deleteUserStore/permission/admin/manage

deleteUserStoresSet/permission/admin/manage

editUserStore/permission/admin/manage

editUserStoreWithDomainName/permission/admin/manage

getAvailableUserStoreClasses/permission/admin/manage

getSecondaryRealmConfigurations/permission/admin/manage

getUserStoreManagerProperties/permission/admin/manage

testRDBMSConnection/permission/admin/manage



OAuthAdminServicegetAllOAuthApplicationData/permission/admin/manage

getAllowedGrantTypes/permission/admin/manage

getAppsAuthorizedByUser/permission/admin/login

getOAuthApplicationData/permission/admin/manage

getOAuthApplicationDataByAppName/permission/admin/manage

getOauthApplicationState/permission/admin/manage

isPKCESupportEnabled/permission/admin/manage

registerOAuthApplicationData/permission/admin/manage

registerOAuthConsumer/permission/admin/manage

removeOAuthApplicationData/permission/admin/manage

revokeAuthzForAppsByResoureOwner/permission/admin/manage

updateApproveAlwaysForAppConsentByResourceOwner/permission/admin/login

updateConsumerApplication/permission/admin/manage

updateConsumerAppState/permission/admin/manage

updateOauthSecretKey/permission/admin/manage



OAuth2TokenValidationServicebuildIntrospectionResponse/permission/admin/manage

findOAuthConsumerIfTokenIsValid/permission/admin/manage

validate/permission/admin/manage



ClaimManagementServiceaddNewClaimDialect/permission/admin/manage

addNewClaimMapping/permission/admin/manage

getClaimMappingByDialect/permission/admin/manage

getClaimMappings/permission/admin/manage

removeClaimDialect/permission/admin/manage

removeClaimMapping/permission/admin/manage

upateClaimMapping/permission/admin/manage



RemoteUserStoreManagerServiceaddRole/permission/admin/configure/security

addUser/permission/admin/configure/security

addUserClaimValue/permission/admin/configure/security

addUserClaimValues/permission/admin/configure/security

authenticate/permission/admin/configure/security

deleteRole/permission/admin/configure/security

deleteUser/permission/admin/configure/security

deleteUserClaimValue/permission/admin/configure/security

deleteUserClaimValues/permission/admin/configure/security

getAllProfileNames/permission/admin/configure/security

getHybridRoles/permission/admin/configure/security

getPasswordExpirationTime/permission/admin/configure/security

getProfileNames/permission/admin/configure/security

getProperties/permission/admin/configure/security

getRoleListOfUser/permission/admin/configure/security

getRoleNames/permission/admin/configure/security

getTenantId/permission/admin/configure/security

getTenantIdofUser/permission/admin/configure/security

getUserClaimValue/permission/admin/configure/security

getUserClaimValues/permission/admin/configure/security

getUserClaimValuesForClaims/permission/admin/configure/security

getUserId/permission/admin/configure/security

getUserList/permission/admin/configure/security

getUserListOfRole/permission/admin/configure/security

isExistingRole/permission/admin/configure/security

isExistingUser/permission/admin/configure/security

isReadOnly/permission/admin/configure/security

listUsers/permission/admin/configure/security

setUserClaimValue/permission/admin/configure/security

setUserClaimValues/permission/admin/configure/security

updateCredential/permission/admin/configure/security

updateCredentialByAdmin/permission/admin/configure/security

updateRoleListOfUser/permission/admin/configure/security

updateRoleName/permission/admin/configure/security

updateUserListOfRole/permission/admin/configure/security



RemoteAuthorizationManagerServiceauthorizeRole/permission/admin/configure/security

authorizeUser/permission/admin/configure/security

clearAllRoleAuthorization/permission/admin/configure/security

clearAllUserAuthorization/permission/admin/configure/security

clearResourceAuthorizations/permission/admin/configure/security

clearRoleActionOnAllResources/permission/admin/configure/security

clearRoleAuthorization/permission/admin/configure/security

clearUserAuthorization/permission/admin/configure/security

denyRole/permission/admin/configure/security

denyUser/permission/admin/configure/security

getAllowedRolesForResource/permission/admin/configure/security

getAllowedUIResourcesForUser/permission/admin/configure/security

getDeniedRolesForResource/permission/admin/configure/security

getExplicitlyAllowedUsersForResource/permission/admin/configure/security

getExplicitlyDeniedUsersForResource/permission/admin/configure/security

isRoleAuthorized/permission/admin/configure/security

isUserAuthorized/permission/admin/configure/security

resetPermissionOnUpdateRole/permission/admin/configure/security



RemoteProfileConfigurationManagerServiceaddProfileConfig/permission/admin/configure/security

deleteProfileConfig/permission/admin/configure/security

getAllProfiles/permission/admin/configure/security

getProfileConfig/permission/admin/configure/security

updateProfileConfig/permission/admin/configure/security



RemoteClaimManagerServiceaddNewClaimMapping/permission/admin/configure/security

deleteClaimMapping/permission/admin/configure/security

getAllClaimMappings/permission/admin/configure/security

getAllClaimUris/permission/admin/configure/security

getAllRequiredClaimMappings/permission/admin/configure/security

getAllSupportClaimMappingsByDefault/permission/admin/configure/security

getAttributeName/permission/admin/configure/security

getAttributeNameFromDomain/permission/admin/configure/security

getClaim/permission/admin/configure/security

getClaimMapping/permission/admin/configure/security

updateClaimMapping/permission/admin/configure/security



RemoteUserRealmServicegetRealmConfiguration/permission/protected/tenant-admin



RemoteTenantManagerServiceactivateTenant/permission/protected/tenant-admin

addTenant/permission/protected/tenant-admin

deactivateTenant/permission/protected/tenant-admin

deleteTenant/permission/protected/tenant-admin

getAllTenants/permission/protected/tenant-admin

getDomain/permission/protected/tenant-admin

getSuperTenantDomain/permission/protected/tenant-admin

getTenant/permission/protected/tenant-admin

getTenantId/permission/protected/tenant-admin

isTenantActive/permission/protected/tenant-admin

updateTenant/permission/protected/tenant-admin



UserIdentityManagementAdminServicechangeUserPassword/permission/admin/manage

enableUserAccount/permission/admin/manage

deleteUser/permission/admin/manage

disableUserAccount/permission/admin/manage

getAllChallengeQuestions/permission/admin/manage

getAllPromotedUserChallenge/permission/admin/manage

getAllUserIdentityClaims/permission/admin/manage

getChallengeQuestionsOfUser/permission/admin/manage

isReadOnlyUserStore/permission/admin/manage

lockUserAccount/permission/admin/manage

resetUserPassword/permission/admin/manage

setChallengeQuestions/permission/admin/manage

setChallengeQuestionsOfUser/permission/admin/manage

unlockUserAccount/permission/admin/manage

updateUserIdentityClaims/permission/admin/manage



AccountCredentialMgtConfigServicegetEmailConfig/permission/admin/login

saveEmailConfig/permission/admin/login



UserInformationRecoveryServiceconfirmUserSelfRegistration/permission/admin/login

getAllChallengeQuestions/permission/admin/login

getCaptcha/permission/admin/login

getUserChallengeQuestion/permission/admin/login

getUserChallengeQuestionIds/permission/admin/login

getUserIdentitySupportedClaims/permission/admin/login

registerUser/permission/admin/login

sendRecoveryNotification/permission/admin/login

updatePassword/permission/admin/login

verifyAccount/permission/admin/login

verifyConfirmationCode/permission/admin/login

verifyUser/permission/admin/login

verifyUserChallengeAnswer/permission/admin/login



EntitlementAdminServiceclearAllAttributeCaches/permission/admin/configuremanage

clearAllResourceCaches/permission/admin/configuremanage

clearAttributeFinderCache/permission/admin/configuremanage

clearAttributeFinderCacheByAttributes/permission/admin/configuremanage

clearCarbonAttributeCache/permission/admin/configuremanage

clearCarbonResourceCache/permission/admin/configuremanage

clearDecisionCache/permission/admin/configuremanage

clearPolicyCache/permission/admin/configuremanage

clearResourceFinderCache/permission/admin/configuremanage

doTestRequest/permission/admin/configuremanage

doTestRequestForGivenPolicies/permission/admin/configuremanage

getGlobalPolicyAlgorithm/permission/admin/configuremanage

getPDPData/permission/admin/configuremanage

getPIPAttributeFinderData/permission/admin/configuremanage

getPIPResourceFinderData/permission/admin/configuremanage

getPolicyFinderData/permission/admin/configuremanage

refreshAttributeFinder/permission/admin/configuremanage

refreshPolicyFinders/permission/admin/configuremanage

refreshResourceFinder/permission/admin/configuremanage

setGlobalPolicyAlgorithm/permission/admin/configuremanage



EntitlementPolicyAdminServiceaddPolicies/permission/admin/configuremanage

addPolicy/permission/admin/configuremanage

addSubscriber/permission/admin/configuremanage

deleteSubscriber/permission/admin/configuremanage

dePromotePolicy/permission/admin/configuremanage

enableDisablePolicy/permission/admin/configuremanage

getAllPolicies/permission/admin/configuremanage

getAllPolicyIds/permission/admin/configuremanage

getEntitlementData/permission/admin/configuremanage

getEntitlementDataModules/permission/admin/configuremanage

getLightPolicy/permission/admin/configuremanage

getPolicy/permission/admin/configuremanage

getPolicyByVersion/permission/admin/configuremanage

getPolicyVersions/permission/admin/configuremanage

getPublisherModuleData/permission/admin/configuremanage

getStatusData/permission/admin/configuremanage

getSubscriber/permission/admin/configuremanage

getSubscriberIds/permission/admin/configuremanage

importPolicyFromRegistry/permission/admin/configuremanage

orderPolicy/permission/admin/configuremanage

publish/permission/admin/configuremanage

publishPolicies/permission/admin/configuremanage

publishToPDP/permission/admin/configuremanage

removePolicies/permission/admin/configuremanage

removePolicy/permission/admin/configuremanage

rollBackPolicy/permission/admin/configuremanage

updatePolicy/permission/admin/configuremanage

updateSubscriber/permission/admin/configuremanage



EntitlementServicegetAllEntitlements/permission/admin/loginmanage

getBooleanDecision/permission/admin/loginmanage

getDecision/permission/admin/loginmanage

getDecisionByAttributes/permission/admin/loginmanage

getEntitledAttributes/permission/admin/loginmanage

XACMLAuthzDecisionQuery/permission/admin/loginmanage



ws-xacmlXACMLAuthzDecisionQuery/permission/admin/manage



UserProfileMgtServiceassociateID/permission/admin/login

deleteUserProfile/permission/admin/loginmanage

getAssociatedIDs/permission/admin/login

getInstance/permission/admin/login

getNameAssociatedWith/permission/admin/loginmanage

getProfileFieldsForInternalStore/permission/admin/login

getUserProfile/permission/admin/login

getUserProfiles/permission/admin/loginmanage

isAddProfileEnabled/permission/admin/loginmanage

isAddProfileEnabledForDomain/permission/admin/loginmanage

isReadOnlyUserStore/permission/admin/loginmanage

removeAssociateID/permission/admin/loginmanage

setUserProfile/permission/admin/login



UserAdminaddInternalRole/permission/admin/configure/security

addRemoveRolesOfUser/permission/admin/configure/security

addRemoveUsersOfRole/permission/admin/configure/security

addRole/permission/admin/configure/security

addUser/permission/admin/configure/security/usermgt/usersmanage

bulkImportUsers/permission/admin/configure/security

changePassword/permission/admin/configure/security/usermgt/passwordsmanage

changePasswordByUser/permission/admin/login

deleteRole/permission/admin/configure/security

deleteUser/permission/admin/configure/security/usermgt/usersmanage

getAllRolesNames/permission/admin/configure/security/rolemgt,/permission/admin/manage/modify/service

getAllSharedRoleNames/permission/admin/configure/security

getAllUIPermissions/permission/admin/configure/security

getRolePermissions/permission/admin/configure/security

getRolesOfCurrentUser/permission/admin/loginmanage

getRolesOfUser/permission/admin/configure/security

getUserRealmInfo/permission/admin/loginmanage

getUsersOfRole/permission/admin/configure/security/rolemgtmanage

hasMultipleUserStores/permission/admin/loginmanage

isSharedRolesEnabled/permission/admin/configure/security

listAllUsers/permission/admin/configure/security/usermgt/users,/manage

listUserByClaim/permission/admin/configure/security

listUsers/permission/usermgt/passwords,admin/manage

setRoleUIPermission/permission/admin/configure/security/usermgt/profileslistUserByClaim/permission/admin/configure/securitylistUsers/permission/admin/configure/security/usermgt/users,/permission/admin/configure/security/usermgt/passwords,/permission/admin/configure/security/usermgt/profilessetRoleUIPermission/permission/admin/configure/security

updateRoleName/permission/admin/configure/security

updateRolesOfUser/permission/admin/configure/security

updateUsersOfRole/permission/admin/configure/securitymanage



MultipleCredentialsUserAdminaddCredential/permission/admin/configure/security/usermgt/passwordsmanage

addUser/permission/admin/configure/security/usermgt/usersmanage

addUsers/permission/admin/configure/security/usermgt/usersmanage

addUserWithUserId/permission/admin/configure/security/usermgtmanage

authenticate/permission/admin/configure/security/usermgtmanage

deleteCredential/permission/admin/configure/security/usermgt/passwordsmanage

deleteUser/permission/admin/configure/security/usermgt/users/admin/manage

deleteUserClaimValue/permission/admin/configure/security/usermgtmanage

deleteUserClaimValues/permission/admin/configure/security/usermgtmanage

getAllUserClaimValues/permission/admin/loginmanage

getCredentials/permission/admin/configure/security/usermgt/passwordsmanage

getUserClaimValue/permission/admin/configure/security/usermgtmanage

getUserClaimValues/permission/admin/configure/security/usermgtmanage

getUserId/permission/admin/configure/security/usermgtmanage

setUserClaimValue/permission/admin/configure/security/usermgtmanage

setUserClaimValues/permission/admin/configure/security/usermgtmanage

updateCredential/permission/admin/configure/security/usermgt/passwordsmanage



IdentityProviderAdminServiceaddOpenID/permission/admin/login

extractPrimaryUserName/permission/admin/login

getAllOpenIDs/permission/admin/login

getPrimaryOpenID/permission/admin/login

removeOpenID/permission/admin/login



XMPPConfigurationServiceaddUserXmppSettings/permission/admin/login

editXmppSettings/permission/admin/login

getUserIM/permission/admin/login

getXmppSettings/permission/admin/login

hasXMPPSettings/permission/admin/login

isXMPPSettingsEnabled/permission/admin/login



IdentitySAMLSSOConfigServiceaddRPServiceProvider/permission/admin/manage

getCertAliasOfPrimaryKeyStore/permission/admin/manage

getClaimURIs/permission/admin/manage

getServiceProviders/permission/admin/manage

removeServiceProvider/permission/admin/manage



IdentitySTSAdminServicereadCardIssuerConfiguration/permission/admin/manage

updateCardIssueConfiguration/permission/admin/manage



IWAAuthenticatorcanHandle/permission/admin/login

login/permission/admin/login



ProvisioningAdminServicegetAllInstalledFeatures/permission/protected/configure/components

getInstalledFeatureInfo/permission/protected/configure/components

getInstalledFeaturesWithProperty/permission/protected/configure/components

getLicensingInformation/permission/protected/configure/components

getProfileHistory/permission/protected/configure/components

performProvisioningAction/permission/protected/configure/components

removeAllConsoleFeatures/permission/protected/configure/components

removeAllServerFeatures/permission/protected/configure/components

reviewProvisioningAction/permission/protected/configure/components



ProfilesAdminServicegetUserProfile/permission/admin/manage/modify/user-profile

putUserProfile/permission/admin/manage/modify/user-profile



SecurityAdminServiceactivateUsernameTokenAuthentication/permission/admin/manage/modify/service

applyKerberosSecurityPolicy/permission/admin/manage/modify/service

applySecurity/permission/admin/manage/modify/service

disableSecurityOnService/permission/admin/manage/modify/service

getScenarios/permission/admin/manage/modify/service

getSecurityConfigData/permission/admin/manage/modify/service

getSecurityScenario/permission/admin/manage/modify/service



STSAdminServiceaddTrustedService/permission/admin/configure/securitymanage

getCertAliasOfPrimaryKeyStore/permission/admin/configure/securitymanage

getProofKeyType/permission/admin/configure/securitymanage

getTrustedServices/permission/admin/configure/securitymanage

removeTrustedService/permission/admin/configure/securitymanage

setProofKeyType/permission/admin/configure/securitymanage



KeyStoreAdminServiceaddKeyStore/permission/admin/configure/securitymanage

addTrustStore/permission/admin/configure/securitymanage

deleteStore/permission/admin/configure/securitymanage

getKeystoreInfo/permission/admin/configure/securitymanage

getKeyStores/permission/admin/configure/security,/permission/admin/manage/modify/service

getPaginatedKeystoreInfo/permission/admin/configure/securitymanage

getStoreEntries/permission/admin/configure/securitymanage

importCertToStore/permission/admin/configure/securitymanage

removeCertFromStore/permission/admin/configure/securitymanage



SCIMConfigAdminServiceaddGlobalProvider/permission/admin/configure/security

addUserProvider/permission/admin/configure/security/usermgt/provisioning

deleteGlobalProvider/permission/admin/configure/security

deleteUserProvider/permission/admin/configure/security/usermgt/provisioning

getAllGlobalProviders/permission/admin/configure/security

getAllUserProviders/permission/admin/configure/security/usermgt/provisioning

getGlobalProvider/permission/admin/configure/security

getUserProvider/permission/admin/configure/security/usermgt/provisioning

updateGlobalProvider/permission/admin/configure/security

updateUserProvider/permission/admin/configure/security/usermgt/provisioning



DirectoryServerManageraddServer/permission/admin/configure/security,/permission/admin/manage/modify/service

changePassword/permission/admin/configure/security,/permission/admin/manage/modify/service

getPasswordConformanceRegularExpression/permission/admin/configure/security,/permission/admin/manage/modify/service

getServiceNameConformanceRegularExpression/permission/admin/configure/security,/permission/admin/manage/modify/service

isExistingServicePrinciple/permission/admin/configure/security,/permission/admin/manage/modify/service

isKDCEnabled/permission/admin/configure/security,/permission/admin/manage/modify/service

listServicePrinciples/permission/admin/configure/security,/permission/admin/manage/modify/service

removeServer/permission/admin/configure/security,/permission/admin/manage/modify/service



LoggedUserInfoAdmingetUserInfo/permission/admin/login



LoggingAdmingetAllLoggerData/permission/protected/configure/logging

getAppenderData/permission/protected/configure/logging

getLoggerData/permission/protected/configure/logging

getSyslogData/permission/protected/configure/logging

getSystemLog/permission/protected/configure/logging

isStratosService/permission/protected/configure/logging

removeSyslogPattern/permission/protected/configure/logging

restoreDefaults/permission/protected/configure/logging

updateAllAppenderData/permission/protected/configure/logging

updateLoggerData/permission/protected/configure/logging

updateSyslogConfig/permission/protected/configure/logging

updateSystemLog/permission/protected/configure/logging



LoginStatisticsAdmingetLoginAttemptsNot available

getUserBasedLoginAttemptsNot available



WorkflowAdminServicegetWorkflow/permission/admin/manage/identity/workflow/definition/view

listWorkflowEvents/permission/admin/manage/identity/workflow/association/view

listTemplates/permission/admin/manage/identity/workflow/definition/view

getTemplate/permission/admin/manage/identity/workflow/definition/view

getWorkflowImpl/permission/admin/manage/identity/workflow/definition/view

listWorkflowImpls/permission/admin/manage/identity/workflow/definition/view

addWorkflow/permission/admin/manage/identity/workflow/definition/create

addAssociation/permission/admin/manage/identity/workflow/association/create

changeAssociationState/permission/admin/manage/identity/workflow/association/update

listWorkflows/permission/admin/manage/identity/workflow/definition/view

removeWorkflow/permission/admin/manage/identity/workflow/definition/delete

removeAssociation/permission/admin/manage/identity/workflow/association/delete

listAssociations/permission/admin/manage/identity/workflow/association/view

listAllAssociations/permission/admin/manage/identity/workflow/association/view

getEvent/permission/admin/manage/identity/workflow/association/view

getRequestsCreatedByUser/permission/admin/manage/identity/workflow/monitor/view

getRequestsInFilter/permission/admin/manage/identity/workflow/monitor/view

deleteWorkflowRequest/permission/admin/manage/identity/workflow/monitor/delete

getWorkflowsOfRequest/permission/admin/manage/identity/workflow/monitor/view



WorkflowImplAdminServiceaddBPSProfile/permission/admin/manage/identity/workflow/profile/create

listBPSProfiles/permission/admin/manage/identity/workflow/profile/view

getBPSProfile/permission/admin/manage/identity/workflow/profile/view

updateBPSProfile/permission/admin/manage/identity/workflow/profile/update

removeBPSProfile/permission/admin/manage/identity/workflow/profile/delete

removeBPSPackage/permission/admin/manage/identity/workflow/profile/delete