Access Method Profiles
Access Method Profiles define what a person sees on their Home page The page that is presented to the user upon login, which contains the tiles that let the user access or navigate to common tasks.. Organizations can change a user's Role Profile based on different criteria. Define the components that a user can access from different locations, corporate or personal devices, or from the mobile app. You do this by mapping a Role Profile to access method types (Known IP, Mobile Device or Workforce Mobile) and corresponding access method values.
- Access Method Profiles extend the capabilities of Known IP Addresses, which are tenant-wide, to the user level.
- When an employee logs in to the system, a Role Profile is assigned based on the employee's Access Method Profile.
- When a manager with multiple roles logs in to the system, the default Role Profile is assigned based on the Access Method Profile, but the Function Access Profile and Display Profile change when the manager changes role.
- If you are using Delegation Authority, the default Role Profile is based on the Access Method Profile that is assigned; it changes when the Delegation Profile changes.
A manager could access all manager functions while at work, including editing the schedule, responding to requests, and creating reports, but only limited functions while at home such as view the schedule but not edit it and view employee requests but not approve or reject them. To configure this example, you can do the following:
- On the Known IP Address page, define an IP address for the work site called WorkIP.
- On the Role Profiles page, define a Role Profile called Manager-work for the manager's work-site activities and another Role Profile called Manager-home for the manager's home activities.
- On the Access Method Profiles page, create a profile that maps access method types and values to the two Role Profiles:
-
Access Method Type Access Method Values Role Profile Known IP WorkIP Manager-work Known IP All Unknown IPs Manager-home
Similarly, you can limit the manager's mobile access to corporate devices by creating an Access Method Profile with the following characteristics:
Access Method Type | Access Method Values | Role Profile |
---|---|---|
Mobile Device | Corporate | Manager-work |
Mobile Device | Personal | Manager-NoAccess |
To create an Access Method Profile:
- From the Main Menu, select Administration > Application Setup > Common Setup > Access Method Profiles.
- On the Application Method Profiles page, click tap Create
. - On the Create Access Method Profiles page, enter a name and description, and click tap Create
- Complete the following:
- Access Method Type — Select from the following:
Known IP — Restrict access to a Known IP Address
Mobile Device — Restrict access to a corporate or personal mobile device.
Mobile App — Restrict access to the UKG Pro Workforce Management mobile application.
Punch The entries on a timecard that mark the beginning (in-punch) or end (out-punch) of a work interval, such as the beginning of a shift or transfer. Status — Restrict access based on whether the employee is punched in or punched out.
- Access Method Value — Depending on the Access Method Type selected, provide the following information.
Access Method Type Access Method Value Known IP Depending on the IP addresses configured on the Known IP Address page, select from the following:
- All Known IP Addresses
- All Unknown IP Addresses
- A listed IP address
Mobile Device Depending on the user's type of mobile device, select from the following:
- Corporate
- Personal
Note: Corporate Devices are owned by your organization compared to Personal Devices that are owned by individual employees. Corporate Devices are configured by an Enterprise Mobility Management (EMM) provider. Refer to the EMM topics in the online help for more information (Administration > Mobile App > EMM > Managed App Configuration).
Mobile App Depending on whether the user is accessing the system from the UKG Pro Workforce Management mobile application:
- Yes
- No
Punch Status Select one of the following:
- In — The employee is punched in and has access only when on-premises.
- Out — The employee is punched out and can access when off-premises.
- Role Profiles — Select a Role Profile that has been defined for your organization.
- Click Tap Save.
- Access Method Type — Select from the following:
- To change entries in the table, select an entry and click tap Edit
, and to delete an entry, select an entry and click tap Delete . - When using multiple mappings, select a row and use Increase Priority
and Decrease Priority to define the precedence of the mappings. - Click Tap Save.
- From the Main Menu, select Administration > Application Setup > Common Setup > Access Method Profiles.
- On the Application Method Profiles page, click tap Edit
. - On the Edit page, select one of the following:
- To edit the existing profile, select Save changes everywhere that the named entity is used
- To duplicate the profile or create a new profile based on the selected profile, select Save as a new named entity.
- As necessary, change the name and description and modify the Access Method Profile Mapping table as described in Create Access Method Profiles.
-
Click Tap Save.
- From the Main Menu, select Administration > Application Setup > Common Setup > Access Method Profiles.
- On the Application Method Profiles page, select a profile and click tap Delete
.
You assign Access Method Profiles in the People Information component.
-
From the Main Menu, select Maintenance > People Information.
-
From the People Information page, select a person from the list and from the Employee section, expand Access Profiles.
-
From the Access Method Profile drop-down list, select a profile.
-
Click Tap Save.
Note: Users can be assigned only one Access Method Profile.