IOM: Manager request access to the subordinate

I have a requirement that managers should be able to request access to resources for their subordinates. OOTB, users can only free resources request and admin can provide resources to others. I can think of a way

All managers is part of a group of IOM.
Give the necessary menu group and permissions to "grant" resource.

I hope that the details of resource objects can be filled by the same manager in this case, because it must be mapped to process details. I don't know how I'm going to add all managers to one group well IOM and with change management, this does not sound like a great way to go about it. In addition, Manager must be "ideally" able to request access to only his subordinates, what will not happen to the approach described above.

Is there a way to do this? Please let me know

Thank you.

Here are three slightly different approaches which require too much customization -
1. instead of create a new jsp just modify the jsp (tjspRequestVerificationTiles.jsp I think) "not allowing users to submit the application for other users. Therefore, write a few lines of code to check that the user is infact the Manager. In this approach, managers will be able to see all the users can choose their but will finally be rejected to create a request.
2. create an approval workflow where if someone else (other than User Manager) has requested approval will go to the User Manager. In this approach eventhough other managers are able to ask of other subordinates, but the resource will not be put into service without the approval of actual carriers.
3. create an approval workflow where if someone else (other then User Manager) asked, while the application is dismissed. So even if an unauthorized user has asked for one, but this request will not go anywhere. You can also send a notification to the user you attempted an unauthorized application.

Tags: Fusion Middleware

Similar Questions

  • Manager Microsoft Access in the auditing keeps popping up for a password when I try to access any program - how to turn off this feature - where is it located?

    Manager Microsoft Access in the auditing keeps popping up for a password when I try to access any program - how to turn off this feature - where is it located?

    Hi Peggy Gore,.

    Welcome to Windows Vista answers Forums!

    Access Manager is a tool to control the types of content that your computer can access on the Internet. After Content Advisor activated, we can consider only rated content that meets or exceeds your criteria. You can adjust the settings according to your preferences.

    If you have set a password and you have forgotten your password, you may need to contact Microsoft Customer service to reset the password.

    For more information, please see the following links to Access Manager:

    Internet Explorer Content Advisor: Frequently asked questions.

    http://Windows.Microsoft.com/en-us/Windows-Vista/Internet-Explorer-Content-Advisor-frequently-asked-questions

    Using Content Advisor to block inappropriate web content.

    http://Windows.Microsoft.com/en-us/Windows-Vista/using-Content-Advisor-to-help-block-inappropriate-Web-content

    Hope this information is useful.

    Jeremy K

    Microsoft Answers Support Engineer
    Visit our Microsoft answers feedback Forum and let us know what you think.

  • Pavilion dv7... How to block programs requesting access to the computer (updater.exe)

    The HP firewall intervenes and asks if I want to accept or deny programs requesting access to the laptop... it's good... but a Trojan horse (updater.exe) after I deny access, comes back every 15 minutes... 5 or 6 active applications if ignored... tired to prohibit access... is there a way HP firewall can be programmed to block these requests of programs known as this malware... thx dudman13

    Hi Dudley,

    This can help identify which application has generated this message.

    Start Notepad and let Windows load completely.  Hold down the Windows key and press R.  For the run box, type msconfig and press ENTER.  In the next window, click the Startup tab, uncheck the box next to each startup item and then click on apply to apply the change.  Reboot the laptop and let it run long enough to see if the message no longer appears.  Reactivate a substantive point both (your security software would be a good first choice), click on apply and restart, then check if the message now.  Keep doing this until you encounter the message following if poster again and you will know that the last program that you define to start is the cause.

    I would like to know what program it is.

    Kind regards

    DP - K

  • Management of access to the PSO

    How should I manage access to the OSP itself (not vCenter).  I'm under 5.5 SSO.  By default, there is an [email protected] account.

    1 should I / can I change the name of this account to something else then the username who has these rights cannot be guessed?

    2. in the event that separate vsphere.local of the accounts for the 2 admins who need direct access to the SSO periodically so that it is possible to see who it was that truly connected so the account [email protected] doesn't have to share?

    Thank you!

    Hello

    In my view, it is necessary for users of the SSO. If AD goes out, what are you doing? I have an account for all the items of the SSO SERVICE. For users of physics I use AD. It is a split approach. That way if the AD goes out I can still manage and use the environment.

    I also always keep [email protected] as a user in vCenter and keep his password in a vault. It's the equivalent of root on a host computer. This way you have a backdoor when everything goes pear-shaped. If the announcement is released, how will you manage your systems? Once more to think about than the break glass.

    I use SSO to service accounts because you have half of the currently VMware management tools, so I use it for all of them. But only the service accounts and an unused admin account until a break glass is necessary (IE. AD is no longer available).

    Best regards
    Edward L. Haletky
    VMware communities user moderator, VMware vExpert 2009, 2010, 2011,2012,2013,2014

    Author of the books ' VMWare ESX and ESXi in the business: Planning Server Virtualization Deployment, Copyright 2011 Pearson Education. ' Of VMware VSphere and Virtual Infrastructure Security: securing the virtual environment ', Copyright 2009 Pearson Education.

    Virtualization and Cloud Security Analyst: The Practice of virtualization, LLC - vSphere Upgrade Saga - virtualization security Table round Podcast

  • Parameters of Lenovo requesting access to the webcam and the microphone every time

    Whenever I have start the Lenovo settings wonder if it could access the webcam and microphonre. It might, but I'm tired of saying things so each time I have start the settings of Lenovo. Can I put this kind of a place permanently?

    It is not with the build 9926, but again, it of broken and responds as soon as menu is selected.

  • My firewall is questioning Container Plugin for Firefox, that requests access to the net. Is - is this legitimate?

    using ZoneAlarm. He asked plugin - container.exe, ver.1.9.2.4, created 22/06/2010.

    This has happened

    Each time Firefox opened

    is after upgrade to 3.6.4

    Yes, it's legitimate.

  • How do I get my apps to allow access to the camera and photi

    • MY iPhone 5s was software updated this morning and found out my snapchat and Kijiji, do not have access to my camera or the photos
    • I have reset my attribution and privacy, it's still doesn't work do not
    • AAND also when I go into settings > privacy > camera it says ' apps that have requested access to the camera will appear here "(mais là pas appers ci-dessous) it's the same for photos under the heading Privacy"»
    • someone also suggested in general > restrictions but do not know my password so I can't try it

    Does anyone have any other suggestions

    Hello

    Delete the apps that you have problems with then download again.

    Open the app, then it should be on the access to the camera.

    See you soon

    Brian

  • Access to the camera? [Android]

    Why is-Reader for Android, requesting access to the camera?

    Because the CreatePDF feature allows to convert digital pictures to PDF. See help of Acrobat Reader for Android: create a PDF file in other formats.

  • Request password to the login screen when you try to access Outlook Express. He has never done this before.

    Request password to the login screen when you try to access Outlook Express. It appeared suddenly.
    (I recently bought phone and set up by my family could have invited)
    In any case-"main identity is the identity alone on the login screen. I need password to manage identities. Can I by pass? This means a first time trip into the bowels of the registry? or I can avoid this.

    original title: express outlook for connection screen password
    Then we will try this password to logon OE.
     
    Outlook Express keeps to request your password
    http://www.dougknox.com/XP/Tips/xp_oe_passwords.htm
     
    Save the password setting will no longer exist in Outlook or Outlook Express
    http://support.Microsoft.com/kb/290684 
  • Policies for approval 11g IOM - approval rule to check the Connection Manager

    Hello

    I have a requirement in which if the applicant of a resource is a Manager, while demand should automatically be approved. However if the applicant is one person other than the owner, then it should be assigned to the Manager for approval. Is it possible to do this verification in the approval rule?

    My idea was to create two trust policies for the same resource with a single policy with auto approve activated if the connection applicant is same as connection of eating of the beneficiary and other policies with the default approval process BeneficiaryManager if the connection of the applicant is different from the connection of the beneficiary. I don't know if the approval rule can be configured to check these values during execution.

    Any kind of help/suggestion is greatly appreciated.

    Concerning
    Deepa

    To do this, you change the task of bpel and specify the condition to jump for the task. In the rule to jump, you must specify if the applicant is responsible for the user (the two values that you get in the payload). Set it up this way auto approve request to the Manager.
    Also be sure to affect the outcome of the BPEL task of condition of approval so that IOM does not wait for the State.

    HTH,
    BB

    Published by: bbagaria on Sep 9, 2011 05:36

  • Terminal to request access code specific app on my iMac OS 10.10 not able to enter the access code

    How to use app-specific code for an OS 10.10 application authentication

    Terminal to request access code specific app on my iMac OS 10.10 not able to enter the access code

    Charles Clark wrote:

    How to use app-specific code for an OS 10.10 application authentication

    You need to say more. Terminal usually wants your admin psswd.

    psswd in terminal will not resonate.

  • Profile Manager - failed to install the remote access profile in the domain environment & multi-Active Network Directory

    Hi all

    I am a COMPUTER administrator for a college and I am trying to fix what seems to be the last hurdle in getting the Profile Manager works correctly.

    I worked for a while now trying to get the Profile Manager capable of pushing the device and profiles for Mac in our group network environment. I was able to operate intermittently, but not often. Most of the time I'm unable to install the remote management profile.

    When you try to install the remote management profile, I give myself one of the two errors-

    The first error is:

    The Installation of the profile failed.

    The «TeleManagement (com.apple.config. » profile (Server.FQDN.mdm:GUID) "could not be installed because of an unexpected error < MDMResponseStatus:500 >

    (Obviously server.fqdn and GUID are placeholders for their actual values)

    The second mistake is:

    The Installation of the profile failed.

    Failed to contact the Protocol SCEP server to ""http://server.fqdn: 1640/CEP / "."

    The server Mac OS X 10.11.4 works

    OS X Server is version 5.1

    Client Mac is for most running 10.10.4

    Here's a quick run down on the environment and the steps I have already taken to solve the problem.

    • The network is an Active Directory with several networks multi-domain environment. I mainly work with two different networks, each associated with one of the two areas.
    • The Mac server hosting the Profile Manager is a Mac Pro. The two network cards is used, each on one of the two networks. The Mac server is joined to the domain in the primary forest.
    • I opened all the ports and IP ranges for Apple's Push Notification service for two on our firewall and tested networks between the two networks to ensure that the AFN is accessible.
    • I created a static DNS entry for the server in the DNS zone for the main domain. I also have a separate DNS zone for the DNS record for the interface on the secondary network. I also confirmed that Macs see the correct IP address of the Mac server for their network.
    • I tried to change the settings for network access for the Profile Manager. The first error seems to happen when the Profile Manager are restricted to the network the Mac client is not connected. This same error also occurs if I open Manager profile access to "all networks".
    • I have experiemented with the different certificate types. In general, I use the self-signed certificates that are generated automatically. In this scenario, I install the profile Trust first (which works seamlessly regardless of network or domain). I also tried to use a certificate for Code signing signed with our own CA to sign the profile of remote management. The same errors will occur no matter what certificates are used.
    • The second error occurs when the access profile manager is limited to the same network that is connected to the Mac client
    • I ran Wireshark captures on several client computers, as well as on the Mac server interfaces and haven't seen any traffic blocked or rejected that seemed related to the Profile Manager
    • I've deleted and rebuilt my OD master
    • I also scoured newspapers for clues Profile Manager and haven't found much
    • In addition, I have also studied the problem and error codes/etc widely and have not found a lot of useful information
    • I don't know there are any other troubleshooting steps I took as well, but I've been question bout this for awhile and I don't remember everyone.

    That's a strange thing - I had it working for Mac on the main network and the domain. However, I discovered that the Mac on the secondary network and the field was unable to download the profile of remote management. This is when I started to change the Profile Manager, access network, which eventually introduce the problem on Macs connected to the primary/field of experimentation network. Change access return settings in Profile Manager does not restore functionality for pimps who worked.

    Another thing odd in this test scenario all - Mac on the network high school/area would not install remote profile unless management I temporarily moved it to the main network (I do not untie / reassign to one the main domain on these Macs) I could get the profile of remote management to install and then pushing profiles has worked. Even more strange, it's the Mac that I had to move temporarily secondary network to the main network to allow remote management profile install only works always as long as the Profile Manager are restricted to the secondary network and 'the Mac'. However, Macs in the same room, on the same network in the same field, using the exact image even get the errors described above.

    The only thing I have not yet done is delete/reconstruction Profile Manager. I would really like to avoid this if possible. Solutions that involve something like Casper or other software integration AD for Macs are also a non-starter.

    I'm happy to elaborate if necessary. I appreciate the help.

    Okay, I think I can find the root cause.

    Before this discovery, I had completely rebuilt Profile Manager. Now, I managed by pushing the management profile remote for Mac in the two fields/networks. However, many of them still refuse to install remote management profile.

    Macs who encounter the problem are all were imaged using NetRestore using an image captured from an another similar iMac. IMac even that was used to build the image has now been reassigned in a test of Mac. I found that when you attempt to register one of the Mac who had received this image it shows already as "registered" when you go to "mydevices" on my Mac server. I also noticed that they all have the serial number of the test Mac when viewing their "register". Among the issues of Macs, I activated the lock of the device from the page "mydevices" for the so-called problematic Mac registered (showing the serial number of the iMac used to create the image) and it locked the iMac used to create the image - not the Mac issue.

    This tells me that the CID (or Mac equivalent) is set on the Mac CID used to create the image for all of the Mac said image was deployed to. If it's a Windows box I have a sysprep prior to deployment or could perform a rearm after the fact. I am unaware of how to perform similar functions in OS X.

    I tested also since on some Macs that do not have this image, and they are able to register and install the profile of Managing remotely with success.

    If anyone has any suggestions on how to reset the CID (the computer ID) under OS X, I'd appreciate it. Thank you.

  • Added Yahoo Toolbar and Add-ons Manager no longer shows the extensions one I can't access the function "get addons".

    I added a Yahoo toolbar for Firefox that has been customized for Frontier Communications. I Ghostery installed as an add-on, and she flashed a message that Yahoo toolbar confused its effective functioning and I would like to disable or uninstall the toolbar. I open the Add-ons Manager to do and much to my surprise he now showed no extension at all, but they all seemed still works! All my plug-ins appear when I look on the Add-ons Manager. I checked the "Get function modules and it tries to load but does not succeed." I am running Firefox 10.0.2.

    Please also try to delete the extensions.* files in the right out of the Firefox profile folder. Firefox will recreate the files and information. Please note that at the next startup, Firefox can request permissions, opening several tabs with each tab corresponds to a detected extension. Select allow the installation, click continue, but click on restart only on the last tab. You can also try to leave out the suspects without selecting modules and continue. I hope it will solve the problem.

    Files & Firefox profile folder

    Another way would be to try a new profile. Firefox stores the data from profile/personal separately from its installation folder. If the new profile is correct, you can later copy/replace files of the old profile in it, for example. the places.sqlite who holds history + information of favorites, the folder of bookmarks which has backups dated only bookmarks, signons3.txt + signons.sqlite which are necessary to restore successfully a saved website names to user/passwords etc. Please note that in this case, although it is also possible to copy the extensions it may be preferable to install again via Tools > Modules search box or AMO.

    Profiles Howto

  • Error: 0 x 80070005 access denied: the requested action requires elevated privileges.

    I downloaded and install a copy of assessment of RC of windows 7 build 7100 and use the key to legitimate windows 7 RC to activate and he succeeded.

    After a few days, my pc hangs and after reset, he began asking to activate windows now. Although pressing ok product error '0x80070005' (I am using the administrator account). Even using the command "slmgr.vbs" does not display ' error: 0 x 80070005 access denied: the requested action requires elevated privileges. "

    Please help and thank you.

    Your question has nothing to do with Windows Update (compared to the upgrade of Windows). Please repost your question here rather: http://social.answers.microsoft.com/Forums/en-US/w7install/threads ~ Robear Dyer (PA Bear) ~ MS MVP (that is to say, mail, security, Windows & Update Services) since 2002 ~ WARNING: MS MVPs represent or work for Microsoft

  • When I try to start the Remote Access Connection Manager in services.msc, the service will not start.

    Rick2425

    When I try to start the Remote Access Connection Manager in services.msc, the service will not start. I get the same error: "Windows could not start the service of connection manager on the local computer remote access: Error 1068: the dependency service or group could start."  Also, I can not restore the system to come and let me run it.

    It is a Dell PP31L, which belongs to a friend who does not connect to the internet because of these error messages.

    Hello Rick2425

    See the thread below and let me know if it helps thanks.

    http://answers.Microsoft.com/en-us/Windows/Forum/windows_vista-networking/error-1068-remote-access-connection-manager/b5155a8a-671e-4d11-8a99-deadc7aee8a1

Maybe you are looking for