Denying a Resource Features of Access Policies

Managing Access Policies 16-7

16.3 Creating Access Policies

You can define an access policy for provisioning resources to users who have roles defined in the policy by using the Access Policy Wizard. To create an access policy: 1. Login to the Oracle Identity Manager Administrative and User Console, and navigate to Advanced Administration.

2. To open the Create Access Policies page, under Policies, click Create Access

Policy . 3. Enter information in the required fields indicated with an asterisk , such as access policy name and description. 4. For the Provision field, select any one of the following options: ■ Without Approval: Selecting this option creates the access policy without request approval. The resources are directly provisioned to the user without any request being generated. ■ With Approval: Selecting this option creates the access policy with request approval. On creating the access policy, a request is created, and provisioning of resources is subject to request approval.

5. Select Retrofit Access Policy to retrofit this access policy when it is created.

If you do not select this option, then existing role memberships are not taken into consideration. Note: The following special characters are not allowed in the access policy name: Semicolon ; Hash Percentage Equal to = Bar | Plus + Comma , Forward slash Back slash \ Single quote Double quote Less than Greater than Note: If you select Retrofit Access Policy, then the access policy is applied to all existing roles that you select in Step 13 of this procedure. 16-8 Oracle Fusion Middleware Users Guide for Oracle Identity Manager

6. Click Continue.

The Create Access Policy - Step 2: Select Resources to provision page is displayed. 7. Specify the resource to be provisioned for this access policy. Search for resources by using the filter search menu. ■ Select the name of the resource from the results table, and then click Add. ■ The names of the desired resources to provision appear in the Selected list. If you want to create an access policy that only denies resources, click Continue without selecting a resource. ■ To unassign the selected resources, highlight the resource in the Selected list and click Remove.

8. Click Continue.

If there is a form associated with this resource, the subsequent pages display the required fields. Otherwise, the Create Access Policy - Step 2: Select Resources to Revoke page is displayed. It is recommended that you do not specify policy defaults for passwords and encrypted attributes. 9. Specify whether or not access policies are to be revoked if they no longer apply. Select the check boxes for the resources you want to revoke automatically from the results table.

10. Click Continue.

The Create Access Policy - Step 3: Selected Resources to deny page is displayed. 11. Use this page to select resources to be denied by this access policy. To select resources to be denied: a. Select the resources from the results table.

b. Click Add to place the resource in the Selected list.

You must select at least one resource to deny if you have not selected any resources to be provisioned. Selecting the same resources to be denied as to be provisioned will automatically unassign them from the resources to be provisioned selection. Similarly, in Step a, assigning the same resources to be provisioned as you have already selected to be denied will automatically remove them from the resources to be denied selection. You can remove the resources that were selected to be denied. You do this by selecting those resources from the Selected list, and clicking Remove. c. Click Continue. The Create Access Policy - Step 4: Select Roles page is displayed. 12. Use the Create Access Policy - Step 4: Select Group page to associate a group with the access policy. 13. To associate a role with this access policy: ■ Select the role from the results table, and then click Add. You must select at least one role. The names of the selected roles appear in the Selected list. ■ You can delete the role name by clicking Remove. 14. Click Continue.