简体   繁体   English

角色层次结构更改实施在ITIM 5.1中如何工作?

[英]How does the Role hierarchy change enforcement works in ITIM 5.1?

"The people affected by the role hierarchy change operation are evaluated against all applicable policies in the system, including policies that are not related to any of the parent roles. As a result, you might find accounts not related to the role hierarchy change that are being enforced." “受角色层次结构更改操作影响的人员将根据系统中所有适用的策略进行评估,包括与任何父角色无关的策略。因此,您可能会发现与角色层次结构更改无关的帐户被执行。”

Can someone explain in layman's term what exactly the above lines are trying to convey, like : 有人可以用外行的术语解释上述几行试图传达的确切内容吗,例如:

when does a role hierarchy change operation occur ? 角色层次结构更改操作何时发生?

what are the applicable policies here and how will change be evaluated ? 这里有哪些适用的政策,以及如何评估更改?

You have just the above part from a longer chapter and it sounds a little bit out of context, but it is not that complicated. 您只需要较长的一章就可以了解到上面的内容,这听起来似乎有些脱离上下文,但这并不复杂。

Role hierarchies have to do with relationships between roles. 角色层次结构与角色之间的关系有关。 In ITIM/ISIM you can define that roles are parents/children of other roles and thus create hierarchies. 在ITIM / ISIM中,您可以定义角色是其他角色的父/子,从而创建层次结构。 It also supports that notion of inheritance, so that for example Provisioning policies that apply to the Parent role, apply to the children roles as well. 它还支持继承的概念,例如,适用于父级角色的置备策略也适用于子级角色。

A role hierarchy change happens when you add a parent or a child in a given role. 在给定角色中添加父级或子级时,角色层次结构发生更改。 If for example you had Role1 and you a provisioning policy that applies to this role, when you add Role2 as a child of the Role1 role, then the provisioning policy will now apply to Role2 too. 例如,如果您有Role1,并且您有一个适用于此角色的供应策略,那么当您将Role2添加为Role1角色的子代时,该供应策略现在也将适用于Role2。

As for the other matter in discussion, lets start with two facts : 至于讨论中的另一件事,让我们从两个事实入手:

  1. You might have a number of provisioning policies in your system. 您的系统中可能有许多配置策略。 Depending on how the policy membership is set up, each one of those can apply to specific roles, groups, or all the persons in your system. 根据策略成员资格的设置方式,每个成员都可以应用于系统中的特定角色,组或所有人员。
  2. In the default ITIM configuration, each time you modify a person, the modifyPerson workflow is executed. 在默认的ITIM配置中,每次修改人员时,都会执行ModifyPerson工作流程。 This can contain a number of nodes, but by default it contains a modifyPerson node and an enforcePolicy node. 它可以包含多个节点,但是默认情况下,它包含ModifyPerson节点和forceforcePolicy节点。 The modifyPerson performs, as the name implies, the modifications on the person object in ITIM. 顾名思义,ModifyPerson对ITIM中的person对象执行修改。 The enforcePolicy node, again as the name implies, evaluates ALL applicable provisioning policies for the person and performs the necessary actions on the persons accounts according to the provisioning policies. 再次顾名思义,forceforcePolicy节点会评估该人员的所有适用设置策略,并根据该设置策略对人员帐户执行必要的操作。

What the sentence you quoted says is that when you add a role (RoleA) as a child of another role (RoleB), the provisioning policy (lets call it Policy1 ) that applies to RoleA, now applies to RoleB also. 您引用的句子说的是,当您将角色(RoleA)添加为另一个角色(RoleB)的子代时,适用于RoleA的供应策略(现在称为Policy1)现在也适用于RoleB。 And if you had a person that was member of the RoleB, now that you perform the role hierarchy change, the policies for this person will be evaluated because ITIM needs to enforce Policy1 for him. 并且,如果您有一个作为RoleB成员的人,现在您执行角色层次结构更改,则将评估该人的策略,因为ITIM需要为其执行Policy1。 However this does not mean that at this time, the only policy that applies to this person, is Policy1. 但是,这并不意味着当前唯一适用于此人的策略是Policy1。 A number of different policies can apply to him and ALL of them will be evaluated at this time. 可以对他应用许多不同的策略,所有这些都会在此时进行评估。 This can lead to changes in other accounts or more changes in the same account of this person. 这可能会导致其他帐户的更改或此人在同一帐户中的更多更改。

By the way, this has been modified a little bit with ISIM 6 , FixPack 3, Intermittent FixPack 11. Now the enforce policy node in the workflow can be configured to only take into consideration the provisioning policies that need to be reevaluated for the specific change that happens and not blindly go through and evaluate everything again. 顺便说一下,已使用ISIM 6,FixPack 3,间歇性FixPack 11对此做了一些修改。现在,可以将工作流中的强制策略节点配置为仅考虑需要针对特定​​更改重新评估的供应策略。发生这种情况,而不是盲目地重新评估所有内容。

声明:本站的技术帖子网页,遵循CC BY-SA 4.0协议,如果您需要转载,请注明本站网址或者原文地址。任何问题请咨询:yoyou2525@163.com.

 
粤ICP备18138465号  © 2020-2024 STACKOOM.COM