5.3 Assigning RBS Role Membership and Scope

Once you have defined the RBS roles needed in your organization, you can assign the membership of each role. In doing so, you specify the scope in which each member can exercise the functions of the role. Depending on the administration application associated with the role functions, the scope is specified either as a context in the eDirectory tree or as an object that represents some other (non-eDirectory) kind of scope.

HINT:If an administration application defines scope in non-eDirectory terms, it will extend the schema of your eDirectory tree to include the needed scope object class. You can then create scope objects as explained in Creating an Object That Represents a Non-eDirectory Scope.

  1. Right-click either the RBS role object or the object that represents the users who you want to assign as role members > click Properties.

    You can assign users as role members individually or in groups, organizations, or organizational units. However, if you want each user to exercise the role within a different scope, you must assign role memberships individually.

  2. On the Role Based Services tab, assign the role memberships you want:

    • For an RBS role object, select the Members of Role page > edit the list of members and their scopes as needed.

      Click Help for details.

    • For a user, group, organization, or organizational unit object, select the Assigned Roles page > edit the list of role memberships and scopes as needed.

      Click Help for details.

    If you want a single role membership to have multiple, non-overlapping scopes (such as two different branches of the eDirectory tree), you must list that role membership multiple times, each with a different scope.

  3. Click OK.