Granulated OIM System Admin Access --- Different levels of admin access
OIM does provide a mechanism for creating different levels of system administration. But I cannot get a combination of "menu" views that allows my help desk people to just look at things. I want them to be able to TRACK Requests, view all users' information and unlock accounts --- yet remove the ablility to update user information and have no access to create/modify, create/modify organizations, create/modify users, create/modify groups, create/modify resources, create/modify deployments and not beable to touch GTC.
When I try to accomplish this I my goal I end up either not being able to track requests (by others) or not look at user data (of others).
0