Realm Roles
IAMS require the following realm roles to be created:
- realm-tenant-admin – role that can create tenant
- tenant-admin – role that can administer role, group, resource, and resource permission in a tenant.
- system-admin – role that can manage user and tenant in the realm. This role is a composite role that contain the realm-tenant-admin role.
Create realm-tenant-admin Role
-
Login to the Web Admin Console and navigate to the realm.
-
Click on
Realm roles
on the side menu:
- Click on
Create role
button
- Enter the following for the role:
- Role name: realm-tenant-admin
- Click on
Save
button to create
Create system-admin Role
-
Login to the Web Admin Console and navigate to the realm.
-
Click on
Realm roles
on the side menu. -
Click on
Create role
button -
Enter the following for the role:
- Role name: system-admin
-
Click on
Save
button to create the role. -
Click on the
Action
dropdown menu on the right hand side of the screen and selectAdd associated roles
submenu.
- Check
realm-management realm-admin
from the list:
- Click on
Assign
button to assign selected roles tosystem-admin
role:
- Click on
Assign Role
button
- Select
Filter by realm roles
from the filter
- Check
realm-tenant-admin
from the list
- Click on
Assign
button to complete the configuration.
Create tenant-admin Role
-
Login to the Web Admin Console and navigate to the realm.
-
Click on
Realm roles
on the side menu. -
Click on
Create role
button -
Enter the following for the role:
Role name: tenant-admin
-
Click on
Save
button to create the role. -
Click on the
Action
dropdown menu on the right hand side of the screen and selectAdd associated roles
submenu. -
Check
realm-management realm-admin
from the list. -
Click on
Assign
button to assign selected roles totenant-admin
role.