Entitlement based certification

If the data from the applications that need to be part of the review are already imported, then the UAR is ready to be configured. To configure an entitlement-focused certification, follow the steps below.

  1. Log in to webconsole and go to Access control > Access certification.
  2. Click on New Access Certification from the side menu and it will render the screen below.

New certification configuration

Complete the form opened using the information from the table below.

Field nameRequired?Description
Access Certification nameYProvide a descriptive name to uniquely identify your campaign.
Type of certificationYDetermines if this is a user or application + entitlement-based review. In this case, select Application.
StatusYIndicates if the campaign is active or not. If the status is Inactive, then you will not be able to execute it.
Scheduled intervalNAllows you to automatically run the campaign at regular intervals such as annually, semi-annually, and quarterly.
Reference start dateNIf the campaign is to be run at regular intervals, then the reference start date is used to determine the date of the next run.
Email templateNEmail template that should be used for notifications.
DescriptionNSummary describing the goals of this campaign.
Manager of access reviewNManager of access review, or the UAR manager, is a person who will be overseeing the execution of the campaign. This person will have access to the UAR campaign dashboard and reports, as well as the ability to delegate requests. The UAR manager is different from a reviewer in a campaign.

Click Next after completing the form as shown in the example below. This will save the UAR configuration and open up additional tabs to complete the review.

New certification configuration

Defining applications participating in the review

  1. Click Next and you will be moved to the next tab, which will allow you to select applications to be reviewed.
  2. From the Managed Systems dropdown, start selecting the applications as shown in the example below. You can select more than one application.

New certification configuration

Defining entitlements for each application

  1. Clicking Next will shift you to the next tab for selecting the entitlements.
  2. Using the two radio buttons shown below, select whether you want all entitlements in all the selected applications to be reviewed or only specific ones. By default, all the entitlements will be reviewed.

New certification configuration

To review a specific set of entitlements, select the Select entitlements from applications option. This will update the UI so you can select entitlements in each of your applications.

New certification configuration

  1. Expand each application by clicking the + sign preceding the application name.
  2. Filter the list of entitlements using a combination of:
    • Name. Searches using the name field with a "starts with" algorithm. Over time, OpenIAM will filter the result.
    • Risk.
    • Metadata type. Provides filtering based on the entitlement type.

As you select the entitlements needed for your review, double-click on them. These entitlements will be moved to another table, shown below, to indicate that they have been selected for the review.

New certification configuration