Default language.

Configuring authorization profiles


As an administrator, you can create, edit, and delete authorization profiles. Authorization profiles associate users who belong to one or more user groups with specific objects. 

By default, a user who is a member of the Administrators user group can create, edit, and delete authorization profiles. 

To understand the concept of authorization profiles and how they can be useful, see  Setting up access control.

Before you begin

  • You must have access to the user groups and objects that to want to include in the authorization profile. 
  • User groups must be available to select during the creation of the authorization profile. Because objects are not a required component, you can create an authorization profile without them and specify the objects at a later time. 

    Information
    Important

    User groups can be created in BMC Helix Portal and imported and synced from an external identity provider (IdP), or synced from another BMC product. Imported and synced groups need to be assigned to relevant roles with permissions in BMC Helix Portal. Additionally, these groups need to be assigned to the authorization profile. Only when users have the appropriate permissions via roles and authorization profiles, they can access BMC Helix Operations Management and perform the necessary functions. For more information, see User identities and Setting up user groups.

    To create an authorization profile

    1. Log in to BMC Helix Operations Management.
    2. On the Administration > Authorization Profiles page, click Create.
    3. Specify a unique name for the authorization profile.
    4. Specify the user groups:
      1. From the User Groups tab, click + Add
      2. Select the user groups to include, and click OK.
    5. Specify the objects by doing one of the following: 
      • To grant unrestricted access to all objects, select the Objects tab, and perform the following steps:
        1. Select Edit from the Associated Objects action menu. 
        2. In the Unrestricted Access for Types box, select one or more options and Save the setting.
      • To grant access to specific objects, select the appropriate tab and click + Add to add the objects.
        Refer to the following list to understand the objects:
    6. Save the authorization profile.

    To edit an authorization profile

    1. Navigate to the Administration > Authorization Profiles page.
    2. From the authorization profile action menu, select Edit.
    3. To update the user groups, select Edit from the user group action menu. 
      1. To add user groups, click + Add, select the user groups to add, and click OK.
      2. To delete user groups, clear the check boxes for the user groups that you want to delete.
      3. Save the changes.
    4. To update the objects, select Edit from the objects action menu.
      1. Select an object type to modify.
      2. Select Edit from the object action menu, and click + Add.
      3. Save the changes.

    To delete an authorization profile

    On the Administration > Authorization Profiles page, do the following:

    From the authorization profile action menu, select Delete.

 

Tip: For faster searching, add an asterisk to the end of your partial query. Example: cert*

BMC Helix Operations Management 26.1