cancel
Showing results for 
Search instead for 
Did you mean: 
Read only

SAP IDM: Limit access to own account

michael_riant
Explorer
0 Kudos
313

Hello,

I would like to limit access to their own account for all IDM users so that they cannot make self-allocations.

Either not the possibility of searching their user or not being able to access the modification screens on their account

Would you have a solution for me, please?

Best regards,

Michael

Accepted Solutions (0)

Answers (1)

Answers (1)

Satheesh_M
Discoverer
0 Kudos

Hi @michael_riant ,
hope you are doing well.

Before going into solutions,
1)I hope in your organization only admin users will have MX_ROLE:ADMIN role
2)You have developer studio access to change the Access Control for Forms (access to com.sap.idm.forms.default package)
3)Your requirement will not be applicable or required for user self service  at all 



In IDM all the modifications will happen via End User UI(in manage TAB). So to restrict own user modification, you should need to change the Access Control settings for Modify Identity Form in com.sap.idm.forms.default package. Instead of default privilege based access control (MX_PRIV:IDS:MANAGE), you can control form access via FILTER method. Here you can filter users by attributes and you can restrict your admin to access Modify Identity Form , If he/she tries to change his own USER ACCOUNT. By this admin can only modify all other users and they can do their job , at the same time they can't change their own access as well. I am not sure this may be the solution for your question, but I hope this will be helpful for you @michael_riant .

Default Forms Package

Satheesh_M_0-1739167947466.png

 

Default Modify Identity form

Satheesh_M_1-1739168162523.png

Access Control Filter to restrict own user modification

Satheesh_M_2-1739168276412.png

Filter Editor
(!(MSKEYVALUE=EntryId)) this filter will restrict admin to access Modify User form, If they select their own account in manage tab.

Satheesh_M_3-1739168315228.png


Satheesh_M_5-1739169399361.png

here you can see that I can't use Modify Identity (Change Identity form) for my Own user account (basically the logged in user). But I can change all other users data using Change Identity form.

Satheesh_M_6-1739169614488.png

 

If you have any questions please let me know. If this details helps you in some way I will be really happy.
Thank you !

Best Regards ,
Satheesh M