...
The following table describes the permissions at Tenant level. These are also referred to as Admin permissions.
Info Note that when you select a node in the Permissions navigator, all the subordinate permissions that are listed under the selected node are also automatically enabled.
Permission level Description of UI menus enabled Admin When the Admin permission node is selected, the following menus are enabled in the management console:
- User Store Management: This permission allows users to add new user stores and manage them with the management console. Note that only secondary user stores can be added using this option. See the topic on user store management for more details.
- Identity Providers: See the topic on working with identity providers for details on how to use this option.- Additionally, all permissions listed under Admin in the permissions navigator are selected automatically.
Admin/Configure When the Admin/Configure permission node is selected, the following menus are enabled in the management console:
- Main menu/PAP: See the topic on working with entitlement for details on how to use this option.
- Main menu/PDP: See the topic on working with entitlement for details on how to use this option.
- Configure menu/Server Roles: See the topic on server roles for more details.
- Tools menu/Tryit (XACML): See the topic on working with the TryIt tool for details on how to use this option.
- Additionally, all permissions listed under Configure in the permissions navigator are selected automatically.Admin/Configure/Security When the Admin/Configure/Security permission node is selected, the following menus are enabled in the Configure menu of the management console:
- Claim Management: See the topic on claim management for details on how to use this option.
- Keystores: See the topic on keystores for details on how to use this option.
- Service Principle (Kerberos KDC): See the topic on kerberos security for details on how to use this option.
- Email Templates: See the topics on email templates for details on how to use this option.
- This permission will also enable the Roles option under Configure/Users and Roles. See the topic on configuring users, roles and permissions for more information.
- Additionally, all permissions listed under Security in the permissions navigator are selected automatically.Admin/Configure/Security/Identity Management/User Management This permission enables the possibility to add users from the management console. That is, the Users option will be enabled under Configure/Users and Roles. Admin/Configure/Security/Identity Management/Password Management This permission enables the Change Password option for the users listed in the User Management/Users and Roles/Users screen, which allows the log in user to change the passwords Admin/Configure/Security/Identity Management/Profile Management This permission enables the User Profile option for the users listed in the User Management/Users and Roles/Users screen, which allows the log in user to update user profiles. Admin/Manage When the Admin/Manage permission is selected, the following menus will be enabled in the management console:
- Main menu/Service Providers: See the topic on working with service providers for details on how to use this option.
- Tools menu/SAML: See the topic on working with the SAML tool kit for more details.
- Additionally, all permissions listed under Admin/Manage in the permissions navigator will be enabled automatically.Admin/Manage/Resources/Browse This permission enables the Browse option under the Registry menu in the main navigator. This option allows users to browse the resources stored in the registry by using the Registry tree navigator. Admin/Manage/Search This permission enables the Search option under the Registry sub menu in the Main menu. This option allows users to search for specific resources stored in the registry by filling in the search criteria. Admin/Monitor When the Admin/Monitor permission node is selected, the following menus are enabled in the management console:
- Monitor menu/System Statistics: See the topic on system statistics for information on how to use this option.
- Monitor menu/SOAP Message Tracer: See the topic on the SOAP tracer for information on how to use this option.
- Additionally, all permissions listed under Admin/Monitor in the permissions navigator will be enabled automatically.Admin/Monitor/Logs When the Admin/Monitor/Logs permission node is selected, the following menus are enabled in the management console:
- Monitor menu/Application Logs
- Monitor menu/System Logs See the topic on system logs for information on how to use these options.
Permissions required to invoke admin services
The following table lists out the various operations that can be performed with different permission levels.
Permission level | Service | Operations |
---|---|---|
Tenant level permissions | ||
/admin | UserStoreConfigAdminService |
|
/admin/configure | EntitlementAdminService |
|
EntitlementPolicyAdminService |
| |
/admin/configure/security | ClaimManagementService |
|
KeyStoreAdminService |
| |
RemoteAuthorizationManagerService |
| |
RemoteClaimManagerService |
| |
RemoteProfileConfigurationManagerService |
| |
RemoteUserStoreManagerService |
| |
SCIMConfigAdminService |
| |
STSAdminService |
| |
UserAdmin |
| |
/admin/configure/security/rolemgt | UserAdmin |
|
/admin/configure/security/usermgt | MultipleCredentialsUserAdmin |
|
/admin/configure/security/usermgt/passwords | MultipleCredentialsUserAdmin |
|
UserAdmin |
| |
/admin/configure/security/usermgt/provisioning | SCIMConfigAdminService |
|
/admin/configure/security/usermgt/users | MultipleCredentialsUserAdmin |
|
UserAdmin |
| |
/admin/login | AccountCredentialMgtConfigService |
|
EntitlementService |
| |
IdentityProviderAdminService |
| |
IWAAuthenticator |
| |
LoggedUserInfoAdmin |
| |
MultipleCredentialsUserAdmin |
| |
OAuthAdminService |
| |
UserAdmin |
| |
UserIdentityManagementAdminService |
| |
UserInformationRecoveryService |
| |
UserProfileMgtService |
| |
XMPPConfigurationService |
| |
/admin/manage | IdentityApplicationManagementService |
|
IdentityProviderMgtService |
| |
IdentitySAMLSSOConfigService |
| |
IdentitySTSAdminService |
| |
OAuth2TokenValidationService |
| |
OAuthAdminService |
| |
wsxacml |
| |
/admin/manage/modify/service | ProfilesAdminService |
|
Super tenant level permissions | ||
/protected/configure/components | ProvisioningAdminService |
|
/protected/manage/modify/tenants | TenantMgtAdminService |
|
/protected/manage/monitor/tenants | TenantMgtAdminService |
|
/protected/tenantadmin | RemoteTenantManagerService |
|
RemoteUserRealmService |
| |
Special cases: These operations require multiple permission levels | ||
/admin/configure/security /admin/manage/modify/service | DirectoryServerManager |
|
KeyStoreAdminService |
| |
/admin/configure/security/rolemgt /admin/manage/modify/service | UserAdmin |
|
/admin/configure/security/usermgt/users /admin/configure/security/usermgt/passwords /admin/configure/security/usermgt/profiles | UserAdmin |
|