Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.
Comment: Published by Scroll Versions from space federationedit and version 2.10

Jump to: 

Table of Contents
maxLevel1
exclude(On this page)|(In this section)|(Related content)|(Get help)
typeflat
separatorpipe

Introduction

Delegated administration Administration is the ability for a site administrator Site Administrator to delegate the duty management of administering select Service Provider(SP) metadata to another person in his/her their organization. This delegated role is called a Delegated Administrator. For organizations with a large number of SPs, or where the SP is operated by a departmental unit, delegated administration allows an organization to spread out the load of metadata management workload.

How delegated metadata administration works

  • A Site Administrator delegates the ability to administer SP metadata to a delegated administrator by providing the eduPersonPrincipalName and e-mail address of a prospective Delegated Administrator.
  • A Site Administrator uses the Delegated Administration feature in Federation Manager to assign ongoing management duties of particular SPs to a Delegated Administrator.
  • A Delegated Administrator may modify and/or delete SP entities assigned to him/her.
  • A Delegated Administrator can create new SP entity.
  • Any metadata update made by a Delegated Administrator must be approved by a Site Administrator for publication to the InCommon metadata.

Step-by-step topics

For Site Administrator:

For Delegated Administrator: 

Considerations

  • A Site Administrator for an organization may not function as a Delegated Administrator for the same organization.
  • A Delegated Administrator for one organization may not function as a Delegated Administrator for another organization.
  • Assigning two Delegated Administrators to manage same entity can have undesirable side effects since the editing of entity descriptors is not constrained by the software in any way.
  • A Site Administrator can not unconditionally delegate responsibility for administering SP metadata; that is, a site administrator must always approve update requests made by a Delegated Administrator.

Access Requirements

  • The Delegated Administrative login interface accepts federated credentials only (i.e., InCommon Operations does not issue passwords to Delegated Administrators).
  • The Delegated Administrator’s IdP must support SAML V2.0 Web Browser SSO (i.e., SAML V1.1 is not supported).
  • The Delegated Administrator’s IdP must release a set of required attributes to the Federation Manager.

In this section

Children Display
depth1

Related content

Content by Label
showLabelsfalse
max10
showSpacefalse
cqllabel = "federationinc-essential-managerreading" and space = "federation"currentSpace()


Get help

Can't find what you are looking for?

Button Hyperlink
iconhelp
titleAsk the community
typeprimary
urlask-the-community