How to restrict delegated administrators to modify their own OIM accounts

Hello - I have a requirement where we need to create delegated administrators for each department. The Delegated Admins are allowed to create and manage user accounts in OIM and OID resource. They can modify user accounts that are part of the organization that they have admin permission on however they should not be able to modify their own accounts. For example, if Org1-Admin is a part of Org1 and have admin priviledges on the Org1 he can create and modify user accounts in Org1 and provision user accounts to OID resource. He can update user profile data and process form data etc. But he should not be able to change his own user profile data and should not be able to get provisioned to OID resource. I am able to set up OIM for the delegated administration part but I am not sure how to restrict the delegated admin for modifying his own profile and restrict OID resource from him. The reason to have this requirement is these delegated admin accounts will act as non-user accounts i.e. they are not tied to any person they are more or less service accounts where if Person1 is assigned as a delegated admin of organization 1 in week 1 he should be able to do the tasks as discussed before using org1-admin account. The next week we may have person 2 doing this job and he should use the same account to login and to do these tasks, these delegated admins will have their own end user accounts that will be tied to their personal ID's and they can modify that account if they are delegated admin :) but not the delegated admin account.
Thanks,

If your self-service application binds to the directory using some special account, like 'superuser_directory' (just an example), then you could allow superuser_directory to modify entries but deny aministrators the ability to modify entries. This means that they connect with their own login to the directory when they modify entries. If you want them to stop modifying their own entries in the application, that's a matter of making the application be aware of that..

Similar Messages

  • HT5114 how can each of my children have their own apple accounts, but share music in itunes?

    Each of my children now has their own IPOD touch.  How can I set their touch's up so that they do not get each other's facetime or text messages, yet they can still share my itunes library music?
    THANKS FOR ANY HELP!

    Have a look here...
    http://macmost.com/setting-up-multiple-ios-devices-for-messages-and-facetime.htm l

  • How to restrict admins to modify their own attribute in OAM

    Is it possible to restrict admins to modify their own attribute in OAM. For example, a admin who has modify right for attribute X but should not be able to modify X for himself.
    Thanks.

    If your self-service application binds to the directory using some special account, like 'superuser_directory' (just an example), then you could allow superuser_directory to modify entries but deny aministrators the ability to modify entries. This means that they connect with their own login to the directory when they modify entries. If you want them to stop modifying their own entries in the application, that's a matter of making the application be aware of that..

  • HT201084 My family shares one Apple ID on multiple devices.  How do I switch everyone over to their own Apple ID without having to erase their iphones and ipads?

    My family currently shares one Apple ID on multiple devices and has for quite awhile.  How do I switch everyone over to their own Apple ID and the Family Sharing without having to erase their iphones and ipads?

    Thank you again for your time, GB.
    I set up individual Apple ID's for my children so that they could have their own Apple ID on their individual iPad minis (gifts from grandparents last year).  When I go to iCloud under Settings, I see my Apple ID listed at the top, then my children's listed under Family Sharing.  So the device is still using my Apple ID for iCloud, iTunes, etc., correct?
    To "assign" their own Apple ID to their own iPad mini, I would need to "Sign Out" from my Apple ID.  When I attempt to do so, I receive a warning that all of the Documents and Data will be lost/deleted. 
    So, instead of doing this, I figured out that I could do what you suggested.  Signing in using a child's Apple ID will allow her/him to use Game Center, FaceTime, and Messages just fine.  However, using their Apple ID for iTunes & App Store proved to be a problem:  Purchased Music and Movies appeared in iTunes, but my Purchased Apps did not appear.  Some Apps even disappeared, e.g. Proloquo4Text (a $99 app to help my son speak with his iPad).
    So I reverted to using my Apple ID for iTunes & App Store, and I get everything that I want, EXCEPT for the iCloud storage for each Apple ID.
    So that's when I started wondering how Family Sharing was really benefiting me ~ It was a lot of work (deleting apps to allow space to download iOS 8, etc) without any benefit that I can see.  UNLESS I find a means to allow me to sign in each iPad's iCloud account with a different AppleID, then perhaps restore the Documents and Data from a backup?  Would that work?
    Thanks.

  • HT4436 we have 5 devices on one itunes account how do I give them each their own icloud account and still share the itunes account?

    we have 5 devices on one itunes account how do I give them each their own icloud account and still share the itunes account?

    You need a unique AppleID for each iCloud account.  So grab some free gmail, hotmail, aol, yahoo or whatever email addresses to make five new AppleIDs.  Now, everybody make an iCloud account for themselves, and keep the existing shared AppleID and password just for use in the iTunes and App Stores.  You can also each use your own unique AppleIDs to make iMessage accounts and keep those separate as well.

  • I have family plan of 5 iphones and all them have the same apple id, the q. is how I can set each one with their own apple id? please advise...

    I have family plan of 5 iphones and all them have the same apple id, the q. is how I can set each one with their own apple id? please advise...

    See How to Stop Sharing an Apple ID.
    (Note that I am affiliated with that site, and some pages contain ads).

  • My young kids have ipads and since I updated the software, but they have their own icloud account, predictive text within their messages shows all my contacts from my iphone but the contacts are not listed as their contacts, how do I stop this?

    My young kids have ipads and since I updated the software, but they have their own icloud account, predictive text within their messages shows all my contacts from my iphone but the contacts are not listed as their contacts, how do I stop this?

    I have deleted the iCloud account under my name on their iPads and replaced with their ones. Apple support said yesterday I needed to click the small 'I' by each name as it came up in the TO box and remove it. After doing rid for each contact under each letter of the alphabet it should remove them from latest contacts. Having done this, although I could not remove groups I had sent, I am not convinced they will not return once I have written a few texts, any ideas?

  • TS3899 I use 3 email accounts.  All were maintained in separate in boxes.   After upgrading to iOS7.0.2, all emails are together in one inbox.  How do I get them back to their own separate in box?

    I use 3 email accounts.  All were maintained in separate in boxes.   After upgrading to iOS7.0.2, all emails are together in one inbox.  How do I get them back to their own separate in box?

    You should be able to see them either way, just as you should have been before you upgraded.
    If you are viewing the consolidated Inbox, you should see something like this near the top of the screen:
    < Mailboxes  All Inboxes      Edit
    Click on the blue "< Mailboxes" to get to the list of separate Inboxes (plus maybe VIP and Flagged virtual mailboxes). Click on one of them to view that Inbox.
    If that does not match what you see on your phone, let us know what you do see.

  • 2 computers, 5 family members with their own iTunes accounts. How do we share purchased iTunes and downloaded CDs with homeshare? (I can't get my old iPod music to all go onto my iPad)

    I have 2 computers - Windows Based
    My husband, myself and the kids all have our own "accounts" on the home computer. This was done to limit certain access when the kids were younger.
    The laptop is pretty much mine. I use both computers for my iTunes music.
    Everyone has their own iTunes account for their music and games. I have been able to get music purchased by my other family members on my iPod in the past if I logged in the home computer under their IDs and attached my iPod. Or, if a family member downloaded a CD, I could get that music thes same way without having to download the CD again under my own login ID. However, I now have an iPad, and I can't transfer music from the iPod to the iPad - specifically that which was downloaded from CDs - not iTunes. And I couldn't get it to go from my iPod to my laptop, although both are authorized computers in the Home Sharing.
    It doesn't seem like the Home Sharing works with the different computer login IDs. The iTunes is universally available regardless of who is logged in, but the libraries vary based on who's user name you are under. I have strugged with importing from one User ID to another, which led me to simply log in under a different family member to get the desired music. There has got to be an easier answer and I'm just not figuring it out.
    I've read the support answers, I've read many of the other responses here as well to those with similiar questions, but I am still struggling.
    Any suggestions?

    If you are completely confident that you didn't hide it, then you purchased those with different apple id. If you completely confident that you purchases with same apple id then you have hidden it. One of the other or you are speaking about a miracle. While miracles are possible they are not very likely. Remember
    Occam's razor?

  • My kids are linked to my itunes account. How do I set them up under their own accounts/credit cards without losing any of their music, apps etc?

    Basically there are 3 users , each with their own iphones using the same username, password and credit card to purchase stuff. I want to give one of them their own personal account and a different card but obviously keep their current songs. They are set up as 3 different users on a Windows PC. Thanks all!!!

    Welcome to the Apple Community.
    If your children are under 13, you should open 2 new accounts for yourself and let them use it. They can use these ID's for iCloud and so have their own email! contacts! calendars etc, but still share your original ID for iTunes for apps, music, etc. You can continue to sync them with your computer.

  • I look after multiple ipads each with their own itunes account. How can I manage them all from one computer.

    I am looking after 20 ipads each with their own itunes account.  Am I able to have more than one itunes account on my computer so that I can sync these ipads when necessary.  We don't always buy our songs on itunes. Sometimes we buy the cds and download them onto itunes so i need to attach them to the computer to sync the songs.  I will need to do this all on my one computer.  Can this be done.  If not, what do you do in this instance.

    Best way to do it is to create a user for each iTunes account.
    http://support.microsoft.com/kb/279783

  • Passing down an iPhone to my child (who is under 13).  Is there a way to get them their own icloud account for iMessage / FaceTime?

    I recently purchased the iPhone & i would like to pass down my iPhone to my daughter (who is 8) so that we can iMessage & FaceTime.  I intend on having my AppleID on the phone, so i can restrict purchases from iTunes & the App store.  Any suggestions on how to get an iCloud account for her, even though she is under 13?

    Each user should have their own icloud account, otherwise they end up getting the same emails, contacts, calendars, notes, reminders, etc. - usually not what you want.  But if all have been sharing the same itunes ID, keep it that way, you can have different IDs for itunes and icloud.
    If you already have another icloud account, and want to set it up on a device, then go to Settings>icloud, scroll to bottom of screen and tap Delete Account.  This only disconnects the device from that account, no data is lost on icloud.  Then enter the account ID that you want to use.
    To create a new icloud account, go to
    http://www.apple.com/icloud/setup/

  • When one or more family members who have been sharing one iTunes account wants to create their own iTunes account can they each upload the music/apps from the shared iTunes on their devices to the new iTunes account?

    When one or more family members who have been sharing one iTunes account wants to create their own iTunes account can they each upload the music/apps from the shared iTunes on their devices to the new iTunes account? 

    Yes. I would clarify your statement about the "shared" iTunes Library though. If you want each iOS device to have its own music library, you should create separate user accounts for them. Read:
    iTunes: How to share music between different accounts on a single computer
    How to use multiple iPods, iPads, or iPhones with one computer

  • If I want to add a family member who is not in my household and has their own itunes account and credit info...

    If I want to add a family member who is not in my household and has their own itunes account and credit info...will all their purchases be charged to my credit card as the Organizer?

    Hi mbostick, 
    Welcome to the Apple Support Communities!
    The only way a family member can use their own funds and not the Organizer’s account for purchases would be with store credit, such as an iTunes gift card. 
    Family purchases and payments
    Making purchases
    After you set up your family, any time a family member initiates a new purchase it will be billed directly to your account unless that family member has gift or store credit. First, their store credit will be used to pay the partial or total bill. The remainder will bill to the family organizer. As the family organizer, any receipts generated by the transaction will be sent to you. Learn more about how iTunes Store purchases are billed.
    Have a great day,
    Joe

  • Gave grandkids Ipads for Christmas.  I need to sync each to my Mac with their own Itune accounts.  I do have them on my computer with their own login.  What is the best way to sync their Ipads?

    I need to sync each of my grandkids IPads to my Mac with their own Itune accounts.  Each grandkid does have a login on my computer that I control.  On their IPads they each set up a ITune account.  What is the best way to sync their Ipads?  Is there something I need to make sure is turned on in their accounts on my computer?

    Hi Jodel,
    Thanks for visiting Apple Support Communities.
    If your grandkids each have a user account on your Mac, you can use the steps in this article to set up syncing with each user account and iPad:
    iTunes 11 for Mac: Set up syncing for iPod, iPhone, or iPad
    http://support.apple.com/kb/PH12113
    You may also find the advice in this article useful:
    How to use multiple iPhone, iPad, or iPod devices with one computer
    http://support.apple.com/kb/ht1495
    Regards,
    Jeremy

Maybe you are looking for

  • Schedule Lines are not getting generated after MRP run.

    Hi, I have an issue where a SA exists for the parent material with item category L (subcontracting). The parent material has a valid BOM and some sub components as well. I see in CS03 that BOM is fine with validity dates for the parent material. A va

  • How to make a 'select .... where id in VARRAY' ?

    Hi all, Someone knows how to create a select using a varray? Like this: declare type arrayNumber is varray(20) of number; lista arrayNumber; v number; begin lista := arrayNumber(1,2,3); select 1 into v from dual where 1 in lista; end; If some one cou

  • Subsinvprocess in the sales order header --- billing tab and in the custom

    Hello All there is a field SubsInvProcess in sales order header - billing- tab and in the customer master - billing tab what was the functionality of this field. I never worked with it kindly help on this one.  Thanks, prasad

  • SELECT to_char(CURRENT_TIMESTAMP,'DD-MM-RRRR HH24:MI:SS') from dual

    Hi, I have a field with timestamp(6) and trying to write substitution variable for it using      SELECT to_char(CURRENT_TIMESTAMP,'DD-MM-RRRR HH24:MI:SS') from dual sql works fine in sql workshop but not when i code it behind page im geting below err

  • I am trying to get my web site uploaded

    I am trying to upload my site using iweb.  I can't get the connection to verify.  Tried everything. I have also tried using filezilla as my hoast suggested.  Got everything set up and found online where iweb saves the files so selected the "Domain Fi