View and update profile (IDR)
The View and update profile (IDR) module allows users to update their profile information and to request changes for themselves or other users.
Changes can include:
New accounts and inventory based on templates and roles
Changes to existing accounts, user information, and group membership
Changes to their own information
These changes can be done manually or they can be modeled after another user.
The View and update profile (IDR) module is enabled by default. To block access to this feature, disable the IDR ENABLED setting.
To configure options that apply to the View and update profile (IDR) module:
Click Manage the system > Modules > View and update profile (IDR).
Configure the options in Table 1, “Modules > Submit requests (IDR) options” as required.
If required, configure event options, listed in Table 2, “View and update profile (IDR) module events that launch interface programs”, that trigger external programs.
Click Update to submit the changes.
Option | Description |
---|---|
IDR DISABLE ACCOUNT SEARCH | Remove advanced search and listing capabilities for network resource group owners and members. When this option is enabled Bravura Security Fabric will only return an exact match. |
IDR DISABLE USER SEARCH | Remove advanced search and listing capabilities for existing users. When this option is enabled Bravura Security Fabric will only return an exact match. |
IDR ENABLED | The switch to turn the View and update profile module on and off. The module is enabled by default. |
IDR NETWORK RESOURCE VALIDATE | For network resources created by the shell extension: Enable this to limit users who can view sub-resources to those who have read permission for the parent resource. For manually created resources, this is controlled by the Users are only allowed to see sub-resources when they read permission for a resource setting. |
IDR NETWORK RESOURCE VALID ONLY | For network resources created by the shell extension: Allow only configured network resources to be eligible of being selected for request access (disabled by default). |
IDR NETWORK RESOURCE SELECT ONE GROUP | When enabled users can only request one group membership at a time when requesting access to network resources. (Disabled by default). |
IDR REQUIRES REASON NEW REQUEST | Requesters must enter a reason when creating a new request. |
MODELAFTER SHOW DIFFS | Enable this to display differences between profiles when using profile comparison by default. |
MODELAFTER VALID ONLY | Enable this to only display valid model users when using profile comparison. Performance can be significantly slower when this option is enabled. |
USER HIST INTERVAL | The number of days of profile history to display. If unspecified, the default value is seven days. |