Definition
Role Recertification is the process of reviewing Role Assignments to verify their compliance. This process is implemented in Memority using Role Recertification Policies that can trigger a workflow on a regular basis or when needed.
The details about the widget allowing to view the recertifications of an Object are described in this page.
Configuration
You can access the Recertification Policy configuration :
-
by clicking on "Portal" → “Recertification Policies”
-
by clicking on "System" → "Configurations" → "Recertification Policies" and perform an import/export.
Properties
|
Property name |
Type |
Mandatory |
Description |
Modifiable after creation |
|---|---|---|---|---|
|
id |
|
YES |
The id is the unique identifier of the Role Recertification Policy It is case sensitive and no special characters (except - or _) are allowed. |
NO |
|
name |
|
YES |
The Object Recertification Policy name. The name may be different from the identifier.Must be at least 4 characters long. |
YES |
|
active |
|
YES |
Allow to toggle activation of the policy |
YES |
|
identityScope |
|
YES |
The Scope of the policy. It will apply to all Role Assignments:
|
YES |
|
roleAssignmentScope |
|
YES |
|
|
|
recertificationPeriod |
|
NO |
A period duration in ISO 8601 format. If provided, the “On the fly” recertification mode will be activated with this period. |
YES |
|
campaignExecutionPlan |
|
NO |
If provided, the “Campaign” recertification mode will be activated with the provided schedule (see “Campaign” recertification below) |
YES |
|
workflowStrategy |
|
YES |
Provide the workflow to be triggered for the recertification |
YES |
Policy Scopes (identityScope + roleAssignmentScope) must be distinct. If a Role Assignment matches several policies, the behavior will not be deterministic.
Example
Read Next
-
Business Policies A Business Policy allows to configure how to trigger actions on Object Types through a Feature with an optional configured Workflow.
-
Object Policies An Object Policy is an Identity Management Service Policy allowing to execute arbitrary actions on Managed Objects, either on a scheduled basis, or in reaction to an Object Operation.
-
Deduplication Policies A Deduplication Policy describes how duplicates should be searched for when creating a managed object.
-
Feature Access Policies A Feature Access Policy is composed of a right which encompasses several Features.
-
Manual Provisioning Policies A Manual Provisioning Policy allows to define that manual provisioning or deprovisioning Workflow is launched when the Role assignment status changes.
-
Object Lifecycle Policies An Object Lifecycle Policy allows to configure rules, on all Object Types, that will alter an Object attribute directly when certain lifecycle events occur.
-
Password Policies A Password Policy determines how passwords should be composed and which rules apply to their lifecycle.
-
Role Request Policies A Role Request Policy allows to define if a Role can be requested, for whom, by whom, and using which Workflow.
-
Workflow Administration Policies A Workflow Administration Policy is composed of a right which encompasses several Features.
-
Memority MFA Account Policies A Memority MFA Policy allows to configure how multi factor authentication should be applied to a population of user
-
Homepage Selection Policies A Memority Home Page Selection Policy allows to configure differents home page depending on user rights.
-
SoD Policies In Memority, SoD rules are based on a SoD policy. A SOD Policy allows to define what kinds of conflicts you can specify and what attributes the system will use to detect them.