12.07.2015 Views

CA Identity Manager Implementation Guide - CA Technologies

CA Identity Manager Implementation Guide - CA Technologies

CA Identity Manager Implementation Guide - CA Technologies

SHOW MORE
SHOW LESS
  • No tags were found...

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Develop a Deployment PlanNote the following when deploying delegated administration for users, groups,and organizations:■■■Limit access to relationship tabs, such as the Admin Roles and ProvisioningRoles tabs, in user-related tasks. These relationship tabs are included indefault user tasks, such as Create User and Modify User. Consider removingthem from the default tasks and using them only in specialized tasks whichare associated with a small number of admin roles.<strong>Identity</strong> <strong>Manager</strong> evaluates each scope rule dynamically; scope informationis not cached. Consider creating scope rules that contain simple directoryqueries to ensure good performance.Evaluate the performance of scope rules by determining how long it takes<strong>Identity</strong> <strong>Manager</strong> to return the objects an administrator can manage.Deploy Delegated Administration for RolesDelegated administration of roles grants the most significant privileges in<strong>Identity</strong> <strong>Manager</strong> and can have the greatest affect (see page 70) onperformance. For these reasons, you should consider deploying delegatedadministration for roles after you have deployed all other functionality.When deploying delegated administration for roles, note the following:■■Limit the number of admin roles, admin role members, and admin roleadministrators to protect the environment and ensure good performance.Once you deploy delegated administration for roles, conduct performanceand scalability tests. Optimize the environment as needed.Chapter 4: Planning Your <strong>Implementation</strong> 63

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!