Option D provides a controlled exception for an administrator who is absent from the external identity provider. A local, or hosted, ZIdentity user can authenticate through Zscaler Authentication Service, and an administrator can assign only the administrative role and Internet & SaaS entitlement required for the temporary task. This preserves explicit identity, scope, and auditability without granting unrelated service access. Zscaler documents how to assign service entitlements to users and groups and how to add Authentication Service administrator roles. Client Connector entitlements govern end-user service access and do not create console-administration privileges. A department is an end-user policy attribute, not an administrative authorization mechanism. OpenID Connect also does not solve the missing identity and role assignment merely by postponing mapping. The temporary account should be removed or disabled when the approved period ends.
================
Contribute your Thoughts:
Chosen Answer:
This is a voting comment (?). You can switch to a simple comment. It is better to Upvote an existing comment if you don't have anything to add.
Submit