Enabling advanced application Access Control
In the following section we will provide you with some design ideas to include in your on premise identity management system to prepare for an advanced application Access Control. We are often asked by our customers how they can manage access to applications both on premise and in the cloud, for example, SaaS.
Usage of MIM 2016
For this reason, we will use the capabilities of MIM 2016 or earlier to provide the complex group building scenarios on premise. The groups are commonly based on roles derived from the contract or contracts of an employee. These can be business or application (technical) roles. Other models like User | Role | Permission or User | Enterprise Role(s) | Application Role (s) | Permissions are also representative examples of such models that provide the correct permissions to a user account.
We can also use the contract to define the representation of an employee in different repositories or applications with a special type of...