Managing Partner Delegations

If your organization has partners that access your system to manage the IT resources you have allocated to them, you can quickly set up your environment to manage those partners using the built-in partner roles and locations.

This topic demonstrates how to manage partner delegations by creating two fictitious partners named "Hendriks Hardware" and "Acme Anvils." We then create two test partner admins and log in to EmpowerID as those partner admins. The purpose of this is to test the delegations. You can follow along, creating these test partners or supply your own. To follow along, replace these two organizations with your actual partners.

Configuring your environment to manage the access of your partners involves the following:

  1. Creating partner locations
  2. Creating test partner admins for each of the partner locations.
  3. Testing the Partner Admin delegations by creating two test people logging in as those people and performing a few basic tasks. If the environment has been correctly configured, the partner admins should only be able to see their locations; they should not be able to see your IT infrastructure or those of any other of your partners. The partner admins should also be able to manage their partner users outside of your intervention.

To create partner locations

  1. From the Navigation Sidebar, navigate to Business Role and Location management page by expanding Identities and clicking Business Roles.
  2. From the Business Role and Location management page, select the Actions tab and then click Create Location.
  3. In the Location Details form that appears, do the following:
    1. Type a name, display name and description for the Location in the Name, Display Name and Description fields, respectively.
    2. Tick Is Assignable so that the option is enabled.
    3. Underneath Parent Location, click the EmpowerID System link to open the Location Selector.
    4. From the Location Selector, search for and select Partner and then click Save to close the Location Selector.
    5. Select Organization from the Location Type drop-down.
    6. Back in the main form, click Save to create the Location.
  4. Repeat steps 3 and 4 above to create locations for each of your remaining partners.

To create test partner admins

  1. Log in to the EmpowerID Web application as an administrator.
  2. From the Navigation Sidebar, navigate to Person Manager by expanding Identities and clicking People.
  3. In Person Manager, click Create Person Simple Mode underneath the Actions pane.
  4. In the Create Person Request form that appears, do the following:
    1. Type a first name and last name for the person in the Last Name and Last Name fields, respectively.
    2. Underneath Primary Business Role and Location, click the Select a Role and Location link to open the Business Role and Location (BRL) Selector.
    3. From the Business Role pane of the BRL Selector, search for and select Partner Admin.
    4. Click Location to show the Location pane of the BRL Selector.
    5. From the Location pane, search for and select the appropriate partner location and then click Select.
    6. Back in the main form, click Save.
  5. Repeat steps 3 and 4 above to create test partner admins for each of your remaining partner locations.
  6. Reset the passwords for each of your test users. For information on resetting passwords, see Resetting Passwords for People.

To test the partner delegations

  1. Log out of the EmpowerID Web application and log back in as one of the partner admins.
  2. Enroll for password self-service reset. This occurs the first time you log in as a new person.
  3. From the Navigation Sidebar, click the Global Search drop-down. You should only see search options for People, Groups and User Accounts.
  4. Search for people by clicking in the Global Search field and pressing ENTER. Since your organization does not yet have any partners, you should see no results.
  5. Repeat by searching for groups and user accounts. Again, you should see no results.
  6. Expand Identities. You should only see menu items for People (Person Manager), Groups (Group Manager) and User Accounts (Account Manager).
  7. Click People to navigate to the Person Management page.
  8. From the Person Management page, click the Create Person Advanced action. This action allows partner admins to create a new partner user, and an Active Directory account for that person, in their partner location.
  9. From the General tab of the Create Person form that appears do the following:
    1. Type a first name, last name and display name for the person in the First Name, Last Name and Display Name fields, respectively.
    2. Type a login in the Login field or click the Login Suggestion button, shown below, to have EmpowerID fill the field with a suggested login.
    3. Underneath Primary Business Role and Location, click the Select a Role and Location link to open the Business Role and Location (BRL) Selector.
    4. From the Business Role pane of the BRL Selector, press ENTER to have EmpowerID return all Business Roles the partner admin can select. You should only see Partner and Partner Admin.
    5. Click Partner to select the role and then click Location to expand the Location pane.
    6. From the Location pane of the BRL Selector, press ENTER to have EmpowerID return all locations the partner admin can see. You should only see the partner location in which the person is the partner admin. You should see no other partner locations or your internal IT structure.
    7. Click the partner location to select it and then click Select to close the BRL Selector.
    8. Click Save to create the new partner. Because partner admins have the delegations to create people in their respective locations, you should see a message stating that the person was successfully created.
  10. Repeat as desired, creating as many test partners as you want.
  11. Reset the password for each of the test partners you created. For information on resetting passwords, see Resetting Passwords for People.
  12. Log out of the Web application as the partner admin.
  13. Log back in to the Web application as one of the test partners and enroll for password self-service reset.
  14. Expand the nodes in the Navigation Sidebar. You should see that you have few options and cannot even view other people in your organization.

  15. Optional - Repeat the above steps, creating as many partner users and partner admins as desired. Your test results should be consistent across the board.
  16. Optional Exercise - In a non-production environment, do the following to have EmpowerID automatically provision user accounts for the partners:
    1. As an administrator, create test OUs for the partner locations you created above. For a general example on creating OUs, see Creating OUs
    2. Map those locations to the appropriate OUs. For a general example on mapping locations to OUs, see Mapping Locations
    3. Create a Provisioning Policy that provisions an Active Directory user account in the appropriate OU for each person assigned to the Partner in Partners Business Role and Location. This policy will provision an AD Account for all partner and partner admins in any location under the Partners location. For a general example, see Creating a RET Policy for AD User Accounts.
    4. Log in to the Web application as one of the partner admins and search for user accounts. You should see one user account for each partner you created.