Access control to the Adminapp

IAM supports configurable, fine-grained authorization to the Adminapp, based on roles or delegations. The configured access controller determines whether an authenticated administrator is allowed to perform an action. Two kinds of Adminapp access controllers are available:

  • Role-based access control: Adminapp access is permitted based on predefined roles assigned to an administrator. These roles are specified and assigned to actions in the Config Editor. They are fixed, set during configuration; changing roles and corresponding actions needs a configuration change. The admin roles are assigned to administrators in the Adminapp with the Administrators Management feature.
  • Realm-based access control: Adminapp access is based on realms, roles, and delegations. Users are partitioned into realms. Administrators are assigned precisely scoped rights within a realm; these rights are expressed as delegations. Assignment of roles and delegations happens dynamically and in runtime via the Realms Management feature in the Adminapp. Actions that are not realm-specific and not controlled by a delegation are still assigned to fixed roles in the IAM configuration.
    This kind of access control addresses the need of organisations to split day-to-day user administration across many teams, business units, tenants or branches, without giving every helpdesk operator access to all users, and without having to create separate IAM instances per group.
  •  
    Notice

    Airlock IAM offers two models to limit administrators to a subset of users by realm: the realm administration model described above and the lightweight simple realm administration model. The latter model is a legacy model. We recommend using the realm administration model whenever possible.

This chapter explains both kinds of access control.