Realm-based access control and administration
Airlock IAM offers two models to limit administrators to a subset of users by realm:
- Realm administration: A flexible model based on first-class realm attributes, realm roles, and delegations of fine-grained permissions. In this model, administrators can manage users across one or more realms (1: n), depending on the roles and delegations assigned to them.
- Simple realm administration: A lightweight model based on a
realmcontext-data item assigned to both administrators and users. Access is granted through ordinary roles. In this model, an administrator can manage only users who belong to the same realm as the administrator (1:1).
The two models cannot be combined in one Adminapp instance.
The simple realm administration model is a legacy model. We recommend using the realm administration model whenever possible.
This chapter decribes both models and explains how to configure them.
Chapter content
Realms versus tenants
Realms provide a way to segregate users. Airlock IAM also supports user segregation through tenants. The following table compares realms and tenants, including their respective use cases, to help you determine which approach best suits your setup.
Realm | Tenant | |
|---|---|---|
Use case |
This use case supports the distributed administration of end-users in a shared application landscape. |
This use case allows saving costs if database pricing is based on database schema. Limitation: All IAM instances must always use the same IAM version. |
User base | Suitable for managing end users within the same organization through different administrative entities or organizational units. | Suitable to manage end-users from different organizations. |
Operation | Realms are created at runtime and do not require activation of a new IAM configuration. | Tenants are explicitly configured. Any change requires activating a new IAM configuration. |
Security |
|
|
Administration |
|
|