Creating IA Service Accounts in EERP

Prev Next

Download PDF Version of the Instructions

Overview

Creating service accounts for Identity Automation requires that an account be created in Munis Cloud Admin and an account created in User Attributes. If you have any questions on creating this account, please contact EERP@education.ky.gov.

Cloud Admin

  1. In Munis Cloud Admin, from the dropdown menu select: User Account Management > Create User.

  2. Create the Identity Automation service account using the provided service account name found in the spreadsheet CUES Service Accounts in EERP. The leading customer number should not be entered when creating the account. For example, the KDE account for Identity Automation is IASrvActKDE. Please refer to column D, Cloud Admin Account Name for your district’s account name. Account names are case sensitive so please use the account name as it appears on the spreadsheet. HINT: Copy and paste from column D to the Username field in Munis Cloud Admin.

  3. Enter the following attributes:

    1. Username: Follow the guidelines in step #2.

    2. Password: Leave as the default. Identity Automation will reset the password.

    3. First Name: Identity

    4. Last Name: AutomationSrvAct

    5. Email: ky_support@idauto.net

    6. Select “User needs a SQL reporting account”

    7. Select Create User

  4. Email both EERP@education.ky.gov and ky_support@idauto.net with the IA Service Account name. Failure to email both accounts will delay in properly configuring the service account.

Create Identity Automation Role in Enterprise ERP

Navigate: System Administration > Security > Roles

  1. Select Add

  2. Create a new role with the following attributes:

    1. Role Key: IA_Service_ACT_CUES

    2. Description: Identity Automation Service Account for CUES

    3. Menu Access: None

Munis System Role

Select the Munis System folder and select Add. Enter the following as seen in the screenshots below:

  1. Allowed to view database detail

  2. Allowed to view system detail

  3. Data Access: Reporting Views access = Full

HR Management / Payroll

Select the HR Management / Payroll folder and select Add. Enter the following as seen in the screenshots below:

  1. View / Maintain employee date of birth

Data Access

Set the data access to the following:

  1. Location maintenance access: Full

  2. Org maintenance access: Full

Category Access

Select the Category Access tab and Update the following under the Employee Master and Terminated Employees columns:

  1. Employee Master Address: Hide SSN (Upd / Del)

  2. Employee Master Main: Hide SSN (Inquiry)

  3. Employee Pay: Hide SSN (Inquiry)

  4. Employee Certifications: Hide SSN (Inquiry)

  5. Employee Master Demographics: Hide SSN (Inquiry)

  6. Employee Master Dates: Hide SSN (Inquiry)

Hint: You can sort by selecting the headers (Category, Employee Master, etc.). After making updates and saving (Accept), select the Employee Master header and sort to verify all the proper categories were updated.

Create IA Service Account in User Attributes

Navigate: System Administration > Security > User Attributes

  1. Select Add

  2. Create a new user with the following attributes:

    1. User ID = CUES Service Account name you created in Cloud Admin.

    2. Name: IA Service Account

    3. Short Name: IA Servi

    4. Initials: ISA

    5. User account status: Enabled

    6. E-mail address: ky_support@idauto.net

    7. Under Roles select IA_Service_ACT_CUES

  3. Select Accept

  4. A warning message may appear “Attributes Not Populated,” you can select No to this message.

  5. An example of the IA Service Account in KDE’s environment can be seen below: