16.2 Configuring Roles and Role Options
Key Takeaways
A role's assignment rule can be a Match List, Filter, Script, Rule, or Population, and it runs during Identity Refresh with the assigned/detected roles option.
Entitlement profiles use attribute rules (filters combined with AND/OR) and permissions; profiles are not shared between roles.
Granted IdentityIQ User Rights on a role (capabilities and scopes) are applied only when Identity Refresh runs with the provision assignments option.
Role versioning needs doArchive set to true in the role create/update/delete business process; archived versions can be rolled back.
Removing entitlements from a role reaches existing holders only through Allow propagation of role changes plus the Propagate Role Changes task.
Configuring Roles and Role Options
Objective 7.2 asks you to configure roles and role options. Roles are created and edited on Setup > Roles (Role Viewer and Role Editor). Behavior that applies to all roles is set on gear icon > Global Settings > IdentityIQ Configuration > Roles, and role types and extended role attributes on Global Settings > Role Configuration.
The Role Editor
| Field or panel | Purpose |
|---|---|
| Name / Display Name / Type | The type decides which panels appear (section 16.1). Changing a type keeps the old data but flags attributes that no longer apply. |
| Owner | An identity or workgroup. It usually approves role changes and role requests, and reviews role certifications. |
| Scope, Description (multi-language), Classifications | Visibility, text, and sensitivity flags |
| Extended role attributes | Custom attributes defined in Role Configuration (section 2.3) |
| Assignment Rule | Automatic assignment through a Match List (identity or application attributes and permissions, with Is Null), Filter, Script, Rule, or Population |
| Required / Permitted / Inherited Roles | The relationships from section 16.1 |
| Entitlements (profiles) | For each application, attribute rules built from filters (field, search type such as equals, like, is null, or contains all for multi-valued, value, ignore case) combined with AND/OR, plus permissions (rights such as create, read, update, delete, execute on a target). A Simple View lets you pick catalog entitlements, and an Advanced View builds filters. Profiles are not shared between roles. |
| Provisioning Policy | Fields needed to provision the role (section 4.2). It removes the uncertainty of OR profiles. |
| Granted IdentityIQ User Rights | Capabilities and scopes given to holders, applied when Identity Refresh runs with the provision assigned roles option |
| Scheduled Events | Activation and deactivation of the role on dates |
| Allow multiple application accounts / Enable multiple assignments | Covered below |
| Disable | Makes the role unavailable. It appears grayed out. |
Roles with pending approval or impact analysis show a red square on the icon. Submitting new changes replaces the pending work item.
Global Role Options (IdentityIQ Configuration > Roles)
- Enable Sunrise / Sunset Dates on Role Assignment – time-limited assignments, run by the Scheduled Assignment business process.
- Enable Sunrise / Sunset Dates on Role Activation – date-based activation or deactivation of the role itself, run by Scheduled Role Activation.
- Days before Sunset expiration to send notification – notify the requester and the recipient before access expires (0 disables it).
- Role create, update, and delete business process – for example, Role Modeler – Owner Approval or Role Modeler – Impact Analysis.
- Show UI option to allow multiple application accounts – a role may use its own or a new account even when another role requires it. Without it, required roles use the top-level role's account.
- Show UI option to allow multiple assignments / Allow multiple assignment for all assignable roles – the same role assigned more than once to one identity. The global setting overrides per-role settings.
- Allow propagation of role changes – records RoleChangeEvents (below).
- Retain assigned entitlements when detected roles are removed / when assigned roles are removed.
- Require comments for all access items in Access Requests.
Making Role Changes Take Effect
| Change | What applies it |
|---|---|
| New or changed assignment rule or profile | Identity Refresh with Refresh assigned, detected roles and promote additional entitlements |
| Provisioning newly assigned roles | Refresh with Provision assignments, or an LCM request |
| Entitlements removed from a role definition | Allow propagation of role changes plus the Propagate Role Changes task, scheduled regularly. It can run policy checks and has a time limit. |
| Granted user rights | Refresh with the provision option |
Role propagation covers the changed role and roles that inherit or require it. The console import -noroleevents option suppresses role-change events for bulk imports (section 3.1).
Versioning and Rollback
Role versioning is off by default. To turn it on, set the doArchive variable to true in the role create/update/delete business process. After every fully activated change, the previous state is archived. On the Role Viewer or Role Editor, open Archived Roles, choose a version, and Roll Back to Archived Role, then Submit. The replaced version is archived too, and approval is still required if role changes need approval. Identities keep their current associations until the next refresh with role options, unless the business process refreshes them.
Worked Example: A Temporary Project Role
A two-month audit project needs the Audit Workspace business role for six people.
- On IdentityIQ Configuration > Roles, confirm that Enable Sunrise / Sunset Dates on Role Assignment is on and that the Scheduled Assignment process is selected.
- Create the role with an owner workgroup, required IT roles for the workspace entitlements, and no assignment rule, because it is request-only.
- Managers request it through LCM with a sunset date at the project end. Days before Sunset expiration notifications warn requesters beforehand.
- On the sunset date, the scheduled process removes the assignment and deprovisions the required access, unless retention options keep assigned entitlements.
Other Role Tools
- Role Mining builds candidate roles from identity data, using attributes marked minable in schemas (section 12.2), and generates assignment rules. If you edit mined roles, check that the generated rules still fit.
- Entitlement Analysis and Impact Analysis show who would gain or lose access before a change.
- Refresh Role Indexes must run before role searches work, and the console
rolerelationshipcommand inspects role relationships.
A new assignment rule on the "Finance Analyst" business role is saved, but no identities receive the role. What must run?
Identity Refresh with "Refresh assigned, detected roles and promote additional entitlements" selected
Account Group Aggregation with Promote managed attributes
The Propagate Role Changes task with no other settings
Perform Maintenance with Prune identity snapshots
A role grants the Help Desk Personnel capability through Granted IdentityIQ User Rights, but members do not receive it. What is missing?
Adding the capability to a QuickLink population
Marking the role as requestable
Running Identity Refresh with the provision assigned roles option, which applies granted capabilities and scopes
Enabling multiple assignments
An administrator removes an AD group from an IT role's profile and wants that group removed from everyone who holds the role. What configuration supports this?
Retain assigned entitlements when assigned roles are removed
Import the role with -noroleevents
Enable sunrise and sunset dates on role activation
Allow propagation of role changes, plus a scheduled Propagate Role Changes task
How is role versioning with rollback enabled?
It is always on; every save creates a version.
By enabling Allow multiple assignments.
By running the Refresh Role Indexes task.
By setting the doArchive variable to true in the role create, update, and delete business process
Sections you finish are checked off in the contents.