Skip to main content

Overview of Manager Approval Methods

MethodDescriptionWhen to Use
Verification by Entitlement GroupA designated entitlement group is created in TruU. Members of this group are responsible for approving device verification requests.When you want a specific set of managers or approvers (not tied to user directory) to review and approve new user device enrollments.
Verification by User’s Manager (User Directory)The device approval request is automatically routed to the user’s manager assigned in the user directory.When your organization’s user directory manager reporting structure is populated and can be used operationally.

Verification by Entitlement Group

Prerequisites
  • You must create an entitlement group in TruU before enabling manager approval workflow.
  • Add all intended approvers (managers or delegated reviewers) to this group.

Create Entitlement Group

  1. In the TruU Admin Console, navigate to Entitlement Groups and Click Add User Entitlement.
  1. Under Add Entitlement Group,
    1. Provide a group name (e.g., “Device Approval Managers”).
    2. Entitlement Group Description
    3. Assign to certain directory groups our add directory users who will be responsible for approving device verification requests.
  2. Save the group.

Set up Manager’s Approval Workflow

  1. Go to User Identification and Click Add Identity Verification Workflow on top right
  1. Provide a workflow name and select the User Self-Service needed
  1. Select Add Identity Verification Step
  1. Choose the approvers needed.
i. For Verification by Entitlement Group, Select the entitlement group created previously. ii. For Verification by User’s Manager, Select a default action if there is no manager saved for that User.
  1. Choose the Allowed Verification Methods for the managers.
  1. Select Require verification to use device for authentication
Note: Devices will be enrolled after completing the self-service portion of enrollment with a state of ‘Unverified’ (which is below ‘Basic’). If a user tries to use this device for authentication, they will be prevented from using it.
  1. Click Save to complete this workflow set up.

Settings: User Identification