You are on page 1of 21

IDM DOCUMENT Completion of training is mandate for using this Document IDM DOCUMENT

IDM Request Guide

Make Sure your training is Complete before Raising access


request via this Booklet

Page 1 of 21
IDM DOCUMENT Completion of training is mandate for using this Document IDM DOCUMENT

Table of Contents

1. IDENTITY MANAGER (IDM)......................................................................................................................... 3


1.1 WHAT IS IDENTITY MANAGER (IDM)?..................................................................................................... 3
1.2 WHO CAN RAISE REQUEST IN IDM?........................................................................................................ 3
2. CONNECTION REQUEST.............................................................................................................................. 4
2.1 SELF-CONNECTION REQUEST FOR NON-PA ACCOUNT..............................................................................4
2.2 STEPS TO BE FOLLOWED FOR RAISING AN ACCESS...................................................................................5
2.3 SELF-CONNECTION REQUEST FOR PA ACCOUNT......................................................................................6
2.4 REQUEST FOR OTHER USER NON PA ACCOUNT (SPOC ACTIVITY).............................................................7
2.5 REQUEST FOR OTHER USER PA ACCOUNT (SPOC ACTIVITY)......................................................................8
3. DISCONNECTION REQUEST......................................................................................................................... 9
3.1 SELF-DISCONNECTION REQUEST FOR NON-PA ACCOUNT.........................................................................9
3.2 SELF-DISCONNECTION REQUEST FOR PA ACCOUNT...............................................................................10
3.3 DISCONNECTION REQUEST FOR NON-PA USER ACCOUNT (SPOC ACTIVITY)............................................12
3.4 DISCONNECTION REQUEST FOR PA USER ACCOUNT (SPOC ACTIVITY)....................................................13
4. RAISING NON PERSONAL ADMIN ACCESS ROLE IN IDM.............................................................................14
5. HOW TO CHECK THE STATUS OF A REQUEST RAISED BY YOU......................................................................16
6. IDM REPORTS........................................................................................................................................... 18

Page 2 of 21
IDM DOCUMENT Completion of training is mandate for using this Document IDM DOCUMENT

1.Identity Manager (IdM)


1.1 What is Identity Manager (IdM)?

IdM is a new AstraZeneca identity and access provisioning tool that will be used to manage
requests for access to applications for AstraZeneca employees to ensure they have what they
need when they start, when they require an access change, or when access changes are necessary
such as departures.

Link to Access IDM :-

https://idm.pa.astrazeneca.com/iam/im/iaccess/ui7/index.jsp

1.2 Who Can Raise Request in IDM?


 All AZ users as Self Service request after completion of mandatory training
 All SPOCS who got “Requester Access” on behalf of others

S.No Scenario Prerequisites In case of Default


1 Self-service request Completion of mandatory training is QCS Owns the right to
(Raised by new joiner) must with QCS Approval for self raise QI against
resource in case of
Compliance Breach

Self-service request NA NA
2 (Raised by Existing user)

Page 3 of 21
IDM DOCUMENT Completion of training is mandate for using this Document IDM DOCUMENT

Completion of mandatory training is QCS Owns the right to


3 Raising request for other must with QCS Approval for user raise QI against
(Raised by SPOC for new Joiner) (New Joiner) resource in case of
Compliance Breach

4 Raising request for other NA NA


(Raised by SPOC for Existing user)

2.Connection Request
Everyone who has access to Identity Manager has the right to request access for their own
account, for example to a file share or SAP. Each of these are known as an entitlement and you
can submit more than one entitlement per request. Only SPOC can place requests for others.

2.1 Self-connection Request for Non-PA account


 Log into IDM, go to Self-service option (Left side of application) and select Access
Request followed by Request Access.
 List of roles will be reflected that are assigned to your profile
 Click on Add Entitlement, in order to add new roles for which you are requesting
 Follow the steps mentioned in [2.2] for raising the request.

Page 4 of 21
IDM DOCUMENT Completion of training is mandate for using this Document IDM DOCUMENT

2.2 Steps to be followed for raising an access


 After Clicking on Add Entitlement a new window will open which will take you to
Search for a group option.
 In the Search for a group Option, specify the criteria against either Name or
Description.
 If you are sure about the role then search with search criteria = , otherwise choose
contains in search criteria and add * at the end or beginning of role or Description,
example: Name = AD-EM-00000205* or Description contains *groups&\DET
 Click on search, you will get a list of result that will match to your criteria
 Select the checkbox placed in front of desire role (multiple roles can be selected).
 Click Select button at the bottom of page.
 The entitlements will be added to your existing role list. If you want further roles
access then again go to Add Entitlement and repeat the above process.
 Once you are done with all the role access then go to Submit tab and Press it.
 After submission of the request you will be able to see a confirmation message saying
“Task Pending” in same window. This means that request is triggered to appropriate
approver for approval.

Page 5 of 21
IDM DOCUMENT Completion of training is mandate for using this Document IDM DOCUMENT

2.3 Self-connection Request for PA account


 Log into IDM, go to Self-service option (Left side of application) and select Parallel
Accounts followed by Request Parallel account Access
 Select search option, your ID will be displayed then click Select.
 List of roles will be reflected that are assigned to your profile initially
 Click on Add Entitlement in order to add new roles for which you are requesting
 Follow the steps mentioned in [2.2] for raising the request.

Page 6 of 21
IDM DOCUMENT Completion of training is mandate for using this Document IDM DOCUMENT

2.4 Request for other User Non PA account (SPOC Activity)


 Log into IDM, go to Users option (Left side of application) and select User access
request followed by Request User Access
 Under search for User option input PRID (Search can be done either by choosing Last
name or First Name also)
 Click on search option, employee details will get displayed below. Click Select.
 List of roles will be reflected that are assigned to employee profile initially
 Click on Add Entitlement in order to add new roles for which you are requesting
 Follow the steps mentioned in [2.2] for raising the request.

Page 7 of 21
IDM DOCUMENT Completion of training is mandate for using this Document IDM DOCUMENT

2.5 Request for other User PA account (SPOC Activity)


 Log into IDM, go to Parallel Accounts option (Left side of application) and select
Request parallel account access
 Under search for User option input PRID (Search can be done either by choosing Last
name or First Name also)
 Click on search option employee details will get displayed below. Click Select.
 List of roles will be reflected that are assigned to employee profile initially
 Click on Add Entitlement in order to add new roles for which you are requesting
 Follow the steps mentioned in [2.2] for raising the request.

Page 8 of 21
IDM DOCUMENT Completion of training is mandate for using this Document IDM DOCUMENT

3.Disconnection Request
All access rights to file shares, SAP, etc. should be relevant to your current job role. Therefore removal
requests must be submitted to remove any access which is no longer required. If a removal request is
placed in error, there is no undo option and you will have to submit a new request for access.

3.1 Self-Disconnection Request for Non-PA account


 Log into IDM, go to Self-service option (Left side of application) and select Access
Request followed by Request Access.
 List of roles will be reflected that are assigned to your profile
 Uncheck Roles that you are going to surrender and then click on submit.
 Comment Screen will come give Comment for Disconnection and Click “YES”.
 After submission of the request you will be able to see a confirmation message saying
“Task Pending” in same window. This means that request is triggered to appropriate
approver for approval.

Page 9 of 21
IDM DOCUMENT Completion of training is mandate for using this Document IDM DOCUMENT

3.2 Self-Disconnection Request for PA account


 Log into IDM, go to Self-service option (Left side of application) and select Parallel
account followed by Request Parallel account Access.
 List of roles will be reflected that are assigned to your profile
 Uncheck Roles that you are going to surrender and then click on submit.
 Comment Screen will come give Comment for Disconnection and Click “YES”.
 After submission of the request you will be able to see a confirmation message saying
“Task Pending” in same window. This means that request is triggered to appropriate
approver for approval.

Page 10 of 21
IDM DOCUMENT Completion of training is mandate for using this Document IDM DOCUMENT

Page 11 of 21
IDM DOCUMENT Completion of training is mandate for using this Document IDM DOCUMENT

3.3 Disconnection Request for Non-PA User account (SPOC


Activity)

 Log into IDM, go to Users option (Left side of application) and select User access
request followed by Request User Access
 Under search for User option input PRID (Search can be done either by choosing Last
name or First Name also)
 Click on search option employee details will get displayed below. Click Select.
 List of roles will be reflected that are assigned to employee profile
 Uncheck Roles that you are going to surrender and then click on submit.
 Comment Screen will come give Comment for Disconnection and Click “YES”.
 After submission of the request you will be able to see a confirmation message saying
“Task Pending” in same window. This means that request is triggered to appropriate
approver for approval.

Page 12 of 21
IDM DOCUMENT Completion of training is mandate for using this Document IDM DOCUMENT

3.4 Disconnection Request for PA User account (SPOC


Activity)
 Log into IDM, go to Parallel Accounts option (Left side of application) and select
Request parallel account access
 Under search for User option input PRID (Search can be done either by choosing Last
name or First Name also)
 Click on search option employee details will get displayed below. Click Select.
 List of roles will be reflected that are assigned to employee profile
 Uncheck Roles that you are going to surrender and then click on submit.
 Comment Screen will come, give Comment for Disconnection and Click “YES”.
 After submission of the request you will be able to see a confirmation message saying
“Task Pending” in same window. This means that request is triggered to appropriate
approver for approval.

Page 13 of 21
IDM DOCUMENT Completion of training is mandate for using this Document IDM DOCUMENT

Page 14 of 21
IDM DOCUMENT Completion of training is mandate for using this Document IDM DOCUMENT

4.Raising Non Personal Admin access Role in IDM


 Log into IDM, go to User (Left side of application) and select User Access request
followed by Request user access to Identity manager
 Under search for User option input PRID (Search can be done either by choosing Last
name or First Name also)
 Click on search option employee details will get displayed below. Click Select.
 List of IDM roles will be reflected that are assigned to employee profile
 Click on Add Admin Role then give ADM-NPA-Administrator. Check it and Select.
 Then Click on Submit.
 After submission of the request you will be able to see a confirmation message saying
“Task Pending” in same window. This means that request is triggered to appropriate
approver for approval.

Page 15 of 21
IDM DOCUMENT Completion of training is mandate for using this Document IDM DOCUMENT

Page 16 of 21
IDM DOCUMENT Completion of training is mandate for using this Document IDM DOCUMENT

5. How to check the status of a request raised by you


 Log into IDM, go to Home option (Left side of application) and select View my
Submitted task.
 Give the date in Submitted between and click search.
 You will be provided with the list of request raised by you between the date gap you
have provided above

Page 17 of 21
IDM DOCUMENT Completion of training is mandate for using this Document IDM DOCUMENT

You can open the incomplete request and check where it is pending.

Page 18 of 21
IDM DOCUMENT Completion of training is mandate for using this Document IDM DOCUMENT

6.IDM Reports
For getting access to IDM Business Object tool connection request for the AD-EM-00055592 should
be raised in IDM

Once you will get the access, you can Log into the below Link with your window credentials

http://bissbi4.americas.astrazeneca.net/BOE/BI
 Go to Document and select the Option Folder as highlighted below
 Expand Public folder >> Identity manager > > General Reports
 List of reports will come. As soon as you will place the cursor near to it, information on the
particular report will get displayed.
 Click your desired option and get your report.

Page 19 of 21
IDM DOCUMENT Completion of training is mandate for using this Document IDM DOCUMENT

Page 20 of 21
IDM DOCUMENT Completion of training is mandate for using this Document IDM DOCUMENT

Page 21 of 21

You might also like