[midPoint] disable "DeleteAll" options in production
Fabian Noll-Dukiewicz
fabian.noll-dukiewicz at veryfy.gmbh
Thu Jul 2 09:18:54 CEST 2026
Hi Steven,
this is quite simple. You can create an administrator role as copy of the default super user user role with the „authorization-3#all“ action. To avoid deletion, you add a second authorization block with the „authorization-model-3#delete“ action and decision „deny“. The following screenshot shows my role configuration:
[image.png]
Kind regards,
Fabian
--
Fabian Noll-Dukiewicz
Spezialist Identity & Access Management | Geschäftsführer
Tel.: +49 152 244 63 211
Email: fabian.noll-dukiewicz at veryfy.gmbh
Web: https://veryfy.gmbh
Von: midPoint <midpoint-bounces at lists.evolveum.com> im Auftrag von Ashwill, Steven L via midPoint <midpoint at lists.evolveum.com>
Datum: Mittwoch, 1. Juli 2026 um 16:13
An: midpoint at lists.evolveum.com <midpoint at lists.evolveum.com>
Cc: Ashwill, Steven L <sashwill at uillinois.edu>
Betreff: [midPoint] disable "DeleteAll" options in production
Is there a way to remove the option or the permissions that allow a super user to "Delete All Objects" or "Delete all Shadows" from the repository menu and other screen where that may exist. There is no reason that I can think of where we would want to do this in production and unfortunately it has happen by accident twice in the last 2 years.
STEVEN L ASHWILL
Software Engineer Coordinator
Administrative Information Technology Services
University of Illinois at Urbana-Champaign
50 Gerty Drive | M/C 673
Champaign, IL 61820
217.265.6337 | sashwill at uillinois.edu
www.aits.uillinois.edu<http://www.aits.uillinois.edu>
Under the Illinois Freedom of Information Act any written communication to or from university employees regarding university business is a public record and may be subject to public disclosure.
_______________________________________________
midPoint mailing list
midPoint at lists.evolveum.com
https://lists.evolveum.com/mailman/listinfo/midpoint
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://lists.evolveum.com/pipermail/midpoint/attachments/20260702/13a5a0f7/attachment-0001.htm>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: image.png
Type: image/png
Size: 74227 bytes
Desc: image.png
URL: <https://lists.evolveum.com/pipermail/midpoint/attachments/20260702/13a5a0f7/attachment-0001.png>
More information about the midPoint
mailing list