How-To decide between Linked Resources and Managed Resources
Introduction
The CoreOne Suite offers different ways to create and manage resources. Approaching the CoreOne Suite’s access management features, it is important to understand which features will be the best match for the use case.
Due to different terminologies used in the target systems supported by the CoreOne Suite, we’ve settled on the terminology “resources”. A resource is a permission that is assignable to an identity within a target system. In the target system Active Directory for example, groups are the equivalent of resources.
This article should aid in deciding between the use of Linked Resources versus Managed Resources.
Step 1 - Understand the differences between resource types
The following documentation is recommended for a better understanding of what resource types are and what the Cleanup Tasks can do:
Step 2 - Understand the limitations when creating new resources
Resources created in within the target system will not be added as resources in the CoreOne Suite automatically. New resources will require some setup before they can be assigned to any Identities, depending on their Management Mode. See: https://itsense.atlassian.net/wiki/spaces/IKB/pages/1796997245 for more information on what these steps are
Linked Resources are created in the target system and have to be linked in the CoreOne Suite Admin UI before any membership assignement is possible
Managed Resources must not be created in the target system, but rather using the CoreOne Suite Admin UI. Any resources created in the target system should be deleted and then recreated within the CoreOne Suite Admin UI, so that the CoreOne Suite may provision the resource into the target system automatically
Task features for resources can be enabled / disabled
on the Target System
on the Resource Type
The task features for Cleanup Tasks to consolidate memberships can be enabled / disabled
on the Target System
on the Resource Type
The Cleanup Tasks should be configured to run on a schedule in order to consolidate memberships
Not every System Connector provides every Management Mode
Step 3 - Identify the use case
Where is the resource lifecycle going to be managed?
Target System → Linked Resources
CoreOne Suite Meta Directory → Managed Resources
Using both Management Modes at the same time is also possible. It might be necessary to mange already existing resources as Linked Resources and new ones as Managed Resources, for example.
Frequently Asked Questions
© ITSENSE AG. Alle Rechte vorbehalten. ITSENSE und CoreOne sind eingetragene Marken der ITSENSE AG.