Previous Topic: Identify Suspected ResourcesNext Topic: Identify Excess Privileges


Identify Suspect Role Definitions

This option identifies roles that are owned by many types of users or suspected users; that is, users possess roles but do not seem to comprise a homogeneous group.

The following table describes the fields in the window:

 

Criteria

Description

Criteria

Maximum number of roles to propose

Limits the maximum number of roles displayed to no more than the absolute indicated number, preventing display of an unmanageable number of suspects.

Maximum percent of roles to propose

The percentage of roles to display out of all that meet the criteria.

Minimum number of users per role

Indicates the minimum number of users for each suspect role.

Minimum number of resources per role

Each role has at least the indicated number of resources.

Evaluation Weights

Organization

Enter a value on a scale of 1 to 10 where 10 is the greatest value.

Organization Type

Enter a value on a scale of 1 to 10 where 10 is the greatest value.

Country

Enter a value on a scale of 1 to 10 where 10 is the greatest value.

Location

Enter a value on a scale of 1 to 10 where 10 is the greatest value.

Title

Enter a value on a scale of 1 to 10 where 10 is the greatest value.

Cost Center

Enter a value on a scale of 1 to 10 where 10 is the greatest value.

The following is a typical configuration window showing results after running this option.

The Role Engineer can now examine each role one-by-one to determine if in fact any suspected role is not in compliance.