From the Available Organizations list, select one or more organizations, and

15-12 Oracle Fusion Middleware Users Guide for Oracle Identity Manager 7. You can modify some permissions that have attribute-level settings. To do so:

a. Select the permission, for example, Modify User Profile, and click Edit

Attributes on the toolbar. The Attribute Settings window is displayed with a list of all user attributes.

b. Select the attributes that you want to allow the user to modify, and click Save.

8. Click Next. The Policy Assignment page is displayed with a table that contains the

roles that are assigned to this policy.

9. To add a role to the policy, click Add. Alternatively, from the Actions menu, select

Add . The Assign Roles window is displayed. 10. Search for role in the Assign Roles window, select the role or roles that you want to assign to the policy, and click Add. The role is added to the policy assignment table. The authorization Policy will be enabled for all the members of the assigned roles. To remove a role from the policy, select the role in the policy assignment table, and click Remove. 11. Click Next. The Confirmation page is displayed with Basic Policy Information and details about permissions, data constraints, and assignments.

12. Click Finish. The authorization policy is created.

15.2.3 Creating Authorization Policies Based on Existing Policies

You can create an authorization policy by using the general, permissions, data constraints, and assignment information from another authorization policy already existing in Oracle Identity Manager. To do so: 1. Search for the authorization policy from which you want to use information to create another policy.

2. Select the policy. From the Actions menu, select Create Like. The Authorization

Policy wizard is displayed. 3. In the Basic Policy Information page, edit the Policy Name, Description, and Entity Name fields to specify new values. 4. Perform the steps to complete the wizard as described in Creating Custom Authorization Policies on page 15-5.

15.2.4 Viewing and Modifying Authorization Policies

You can view and modify authorization policies, and change the general information, permissions, data constraints, and assignments of the authorization policies. To do so: 1. In the Authorization Policy tab of the Administration Console, in the left pane, search for authorization policies. The policies matching the search criteria are displayed in the search results table. Note: The options for authorization policy modification changes dynamically based on the entity type selected for the policy. In this procedure, the example of an authorization policy for role management is used.