Use case - Set up a realm administration

In this use case, we set up the realm administration environment for company X, including the two locations North and South.

Realm administration setup

  • Two realms, corresponding with the users in locations North and South.
  • One realms manager, who manages all realms, roles and delegations.
  • A helpdesk staff employee per location/realm
  • A user manager per location/realm

See the table and the figure below:

User

Role

Realm

Permissions

Where configured

Realms manager

realms-manager

not applicable

Global role that allows to manage realms

In the IAM configuration
(Config Editor)

admin

  • admin-realm
  • realm-north
  • realm-south

All available permissions

In the Adminapp
(Realm Management)

Helpdesk staff in location North

helpdesk-north

realm-north

Permissions required for simple helpdesk tasks:

  • listUsers
  • viewUser
  • lockUser
  • unlockUser

In the Adminapp
(Realm Management)

User manager in location North

useradmin-north

realm-north

Permissions required to manage end-users in the respective realm:

  • createUser
  • deletePassword
  • deleteUser
  • editUser
  • editUsername
  • editUserRealm
  • listUsers
  • manageAdminRoles
  • orderPassword
  • triggerPasswordReset
  • unorderPassword
  • viewAirlock2FAActivationSecret
  • viewContextData
  • viewToken
  • viewUser
  • viewUserLogs

In the Adminapp
(Realm Management)

Helpdesk staff in location South

helpdesk-south

realm-south

Permissions required for simple helpdesk tasks:

  • listUsers
  • lockUser
  • viewUser
  • unlockUser

In the Adminapp
(Realm Management)

User manager in location South

useradmin-south

realm-south

Permissions required to manage end-users in the respective realm:

  • createUser
  • deletePassword
  • deleteUser
  • editUser
  • editUsername
  • editUserRealm
  • listUsers
  • manageAdminRoles
  • orderPassword
  • triggerPasswordReset
  • unorderPassword
  • viewAirlock2FAActivationSecret
  • viewContextData
  • viewToken
  • viewUser
  • viewUserLogs

In the Adminapp
(Realm Management)

To build this realm administration setup:

  • First, create a Realms Manager user who can create and edit all realm roles, realms and delegations.
  • Next, build your realm administration environment.

Configure and create the Realms Manager user

You configure the Realms Manager user partly in the Config Editor, partly in the Adminapp.

Perform the following steps (as superadmin user).

In the Config Editor

Create the global realms-manager user role and assign it to the Realm Management actions. To do this, perform the following steps:

Create realms-manager user role

  1. In the Config Editor, go to
    Adminapp >> Users
  2. Scroll to the User Details Page - General section.
  3. Go to the Available User Roles property and add realms-manager to the roles list.

Assign the realms-manager user role to Realm Management actions

  1. In the Config Editor, go to
    Adminapp >> Access Control
  2. Scroll to the Realm Management section.
  3. Enter realms-manager to all listed actions (such as Create Realm Role, View Delegations). Do not change the properties Superadmin Role and Delegations Repository.
  4. Activate your new configuration

In the Adminapp

Assign the “realms-manager” role to a user. Proceed as follows:

Create a Realms Manager user

  1. Log in as superadmin to the Adminapp and open the Users dialog.
  2. Open the Users details page of the first regular admin user you created during bootstrapping. This is the user who holds the “admin” realm role.
  3. Select the Profile tab and assign this user the “realms-manager” role.
  4. Your first admin user now holds the roles “admin” and “realms-manager”. Both roles are required to perform a Realms Manager function, see the table above.

Build the realm administration environment

Prerequisites

In our use case, building the realm administration environment can be done by all users that hold both the “admin” and “realms-manager” roles (see the table above).

Steps

Any realm manager can only assign and unassign

  • Roles that they hold themselves, or that are subroles of the roles they hold.
  • Within a specific realm: Permissions that they already have themselves through another delegation for this realm.

We must therefore

  1. First, link the “admin” role with each realm we want to create, holding all permissions, via delegations. In our use case, these are the realms “realm-north” and “realm-south”.
  2. Subsequently create the required roles as subroles of the “admin” role.
  3. Then connect each role with a realm and select the permissions relevant for the role in this realm, again via delegations.
  4. Finally, assign the realm roles to the respective users.

Proceed as follows:

  1. In the Adminapp, open the Realm Management dialog.
  2. Select the Delegations tab.
  3. Click Create Delegation to connect the “admin” role with realm “realm-north”.
  4. In the Create Delegation window:

    • Select the “admin” role.
    • Create the new realm “realm-north”.
    • Select all permissions.
    • Click Create to create the delegation.
  5. Now create a second delegation to connect the “admin” role with realm “realm-south”:
    • Click Create Delegation.
    • Select the “admin” role.
    • Create the new realm “realm-south”.
    • Select all permissions.
    • Create the delegation.
  6. Next, create the realm roles “helpdesk-north”, “useradmin-north”, “helpdesk-south”, and “useradmin-south”:
    • In the Realm Management dialog, select the Realm Roles tab.
    • Click Create Role.
    • In the Create Realm Role window:
      • Select “admin” as parent role.
      • Enter the respective role name (helpdesk-north, useradmin-north, helpdesk-south or useradmin-south) in the Role Name field.
      • Click Create to create the realm role.
    • Repeat the above steps until you have created all roles.
  7. Next, connect each role with a realm and select the permissions relevant for the role in this realm, by creating delegations.
  8. Perform the following steps for each realm role:

    • Select the Delegations tab.
    • Click Create Delegation.
    • In the Create Delegation window:
      • Select the respective role, e.g., “helpdesk-north”.
      • Next, select the respective realm. For “helpdesk-north”, this is “realm-north”.
      • Next, select the permissions required for this role in this realm, from the list. Here, listUsers, viewUser, lockUser, unlockUser. See also the table above.
      • Click Create to create the delegation.
    • Repeat the above steps for the roles “useradmin-north”, “helpdesk-south”, and “useradmin-south”.
  9. Create the user accounts for the users to which you want to assign these roles.
  10. Assign them the corresponding roles.