Identity Management System¶
Should you need to apply for access to projects or datasets that are not managed by the Data Analytics Platform, or if you need to add a user to a project that you control, then this may require using the Identity Management System (IDM).
An official guide to the identity system used is available here.
Applying for access using the IDM¶
If possible, we recommend simply asking the project/dataset owner to add you to the project or dataset in question, but the following provides a brief summary of how to apply through the IDM:
Log in at identity.ku.dk.
Click on the
Manage My Accessor theManage User Accessbutton. Which button you see will depend on whether you own any groups yourself.If you clicked on the
Manage User Accessbutton then you must next search for your own UCPH username (e.g.abc123) and then click on the check mark to the left your name once. Wait for the check mark to turn green, click theNextbutton, and then proceed with the steps described above.
Search for and locate the group corresponding to the resource you wish to access. Depending on the kind of resource you wish to apply for access to, the names will differ somewhat:
A server group will typically start with the prefix
SRV-and end with-users, for exampleSRV-esrumhead-usersfor the Esrum head node.A project group will typically start with
COMP-PRJ-, for exampleCOMP-PRJ-cbmr_sharedfor the/projects/cbmr_sharedproject.A dataset group will typically start with
COMP-DATASET-and end with-ro, for exampleCOMP-DATASET-cbmr_shared-rofor the/datasets/cbmr_shareddataset containing shared resources.
Warning
In general, you should not be applying for access to projects with suffixes like
-Owners,-admin, or-rwunless explicitly told to do so by the owner(s) of those resources. These suffixes indicate administrative groups and your requests will therefore be denied if you apply without reason.Click once on the check-mark to the left of the name of the group in the resulting list. Wait for the check mark to turn green and then click the
Nextbutton. If you get a yellow popup with the messageCannot Add Access Item. The item you are trying to select is already assigned, then you have already been granted access to this resource.If you get a
Select Rolepopup, asking you toSelect the business role to assign to this permitted role., then we recommend that you pick aSTAFF-ORGrole from the list.
Finally, click the
Submitbutton to submit your request.Wait for your request to be processed.
Adding users to a group using the IDM¶
Log in at identity.ku.dk.
Click on the
Manage User Accessbutton. If you instead have aManage My Accessbutton, then you do not control access to any groups and will not able to carry out these steps.Search for the username of the user you want to add to a group, click once on the check-mark to the left of the name of the user in the resulting list. Wait for the check mark to turn green and then click the
Nextbutton.Search for and locate the group corresponding to the resource you wish to grant access to. See the corresponding step in the previous guide, for a brief description of how groups are named.
Click once on the check-mark to the left of the name of the group in the resulting list. Wait for the check mark to turn green and then click the
Nextbutton. See above if you get aCannot Add Access Item.or aSelect Rolepopup.Finally, click the
Submitbutton to submit your request.Wait for your request to be processed.