Skip to main content

RoleMapping

Defines a naming rule to create a single role in a specific category based on a property. The naming rule also creates a navigation rule that gives the property to the target user when the single role is assigned.

Examples

Additional condition

The following example uses WhereExpression to condition the application of the rule.

info

NETWRIX recommends using this property only when the properties from the rule items don't suffice.

Here, according to the naming convention, create a single role for each group (memberOf value) whose dn starts with SG_ and whose dn's second part (between two _) is made of three characters.

<RoleMapping Identifier="AD_dn" Policy="Default" Property="AD_Entry:memberOf" ResourceType="AD_Entry_NominativeUser" WhereExpression="C#:resource:return resource.dn?.Split('_')[1].Length == 3;" >
<Rule>
<Item Property="AD_Entry:dn" Operator="StartWith" Value="SG_"/>
</Rule>
</RoleMapping>

Properties

PropertyDetails
ApprovalRequired default value: falseType: Boolean Description: Indicates that the generated role must be approved before being used by a policy.
ApprovalWorkflowType default value: NoneType: ProvisioningPolicyApprovalWorkflow Description: Indicates the number of validation to give to a manual role (from 0 to 3 inclusive). The value 4 is used when a manual assignment can't be performed.
Category optionalType: Int64 Description: Identifier of the category.
CategoryDisplayNameBinding optionalType: Int64 Description: Defines the binding used to compute the category display name.
CategoryDisplayNameExpression optionalType: String Description: References the C# or literal expression used to compute the category display name. See C# expressions for details.
CategoryIdentifierBinding optionalType: Int64 Description: Binding used to compute the category identifier.
CategoryIdentifierExpression optionalType: String Description: C# or literal expression used to compute the category identifier. See C# expressions for details.
CommentActivationOnApproveInReview default value: InheritedType: CommentActivationWithInherited Description: Indicates if a comment is enabled when reviewing a request of the role and deciding to approve it. 0 - Disabled 1 - Optional 2 - Required 3 - Inherited: comment activation in the associated policy.
CommentActivationOnDeclineInReview default value: InheritedType: CommentActivationWithInherited Description: Indicates if a comment is enabled when reviewing a request of the role and deciding to refuse it. 0 - Disabled 1 - Optional 2 - Required 3 - Inherited: comment activation in the associated policy.
CommentActivationOnDeleteGapInReconciliation default value: InheritedType: CommentActivationWithInherited Description: Indicates if a comment is enabled when reviewing a non-conforming assignment of the role and deciding to delete it. 0 - Disabled 1 - Optional 2 - Required 3 - Inherited: comment activation in the associated policy.
CommentActivationOnKeepGapInReconciliation default value: InheritedType: CommentActivationWithInherited Description: Indicates if a comment is enabled when reviewing a non-conforming assignment of the role and deciding to keep it. 0 - Disabled 1 - Optional 2 - Required 3 - Inherited: comment activation in the associated policy.
DisplayNameBinding optionalType: Int64 Description: Defines the binding used to compute the role display name.
DisplayNameExpression optionalType: String Description: References the C# or literal expression used to compute the role display name. See C# expressions for details.
HideOnSimplifiedView default value: falseType: Boolean Description: true to hide this role in the basket simplified view. This flag is applied only on automatic assignments.
Identifier requiredType: String Description: Identifier of the role mapping.
IdentifierBinding optionalType: Int64 Description: Binding used to compute the role identifier.
IdentifierExpression optionalType: String Description: C# or literal expression used to compute the role identifier. See C# expressions for details.
ImplicitApproval default value: 0Type: Byte Description: Indicates if the validation steps of the single role can be skipped. 0 - Inherited: implicit approval value in the associated policy. 1 - Explicit: all the workflow steps must be approved. 2 - Implicit: the workflow steps can be skipped if the requester has enough permissions.
ParentCategoryIdentifierBinding optionalType: Int64 Description: Defines the binding used to compute the parent category.
ParentCategoryIdentifierExpression optionalType: String Description: References the C# or literal expression used to compute the parent category. See C# expressions for details.
Policy requiredType: Int64 Description: Identifier of the policy that the rule is part of.
Property requiredType: Int64 Description: Property on which the naming rule will be applied.
ResourceType requiredType: Int64 Description: Resource type on which the naming rule will be applied.
RolePolicy optionalType: Int64 Description: Identifier of the policy used for the roles created by the naming rule.
WhereExpression optionalType: String Description: C# expression returning a boolean, used to condition the application of the naming convention. See C# expressions for details.

Child Element: Rule

Represent the sets of conditions which will determine the enforcement of the naming rule.

Child Element: Item

Represents one of the conditions used to determine the enforcement of the naming rule.

Properties

PropertyDetails
Operator default value: 0Type: QueryComparisonOperator Description: Operator used in the condition for the naming rule enforcement.
Property requiredType: Int64 Description: Property on which the condition for the naming rule enforcement is based.
Value optionalType: String Description: Value used in the condition for the naming rule enforcement.