Default Authorization Policies Role Management

Managing Authorization Policies 15-25

15.3.7 Scheduler

The default authorization policy for the scheduler feature allows users with the System Administrators and SCHEDULER ADMINISTRATOR roles to access all scheduler operations. This policy has the following details: ■ Policy Name: Scheduler Administration Policy ■ Assignee: System Administrators and SCHEDULER ADMINISTRATOR roles ■ Functional security: The permissions are: – Job Create – Job Delete – Job Disable – Job Enable – Job Filter Policy Name Assignee Functional Security Data Security Description Reconciliation Management Administration Policy SYSTEM ADMINISTRATORS and RECONCILIATION ADMINISTRATORS roles The permissions include: Assign Bulk Action Create Act Create User Link Act Link User Search View Event Details These permissions do not support fine-grained attribute-level controls. None Allows users with the RECONCILIATION ADMINISTRATORS or SYSTEM ADMINISTRATORS role to access all reconciliation management actions Reconciliation API Policy SYSTEM ADMINISTRATORS and RECONCILIATION ADMINISTRATORS roles The permissions are: Create Reconciliation Event Delete detected Accounts Get Missing Accounts Ignore Event Link Event to Resource for user Link Event to User Process Reconciliation Event These permissions do not support fine-grained attribute-level controls. None Allows users with the RECONCILIATION ADMINISTRATORS or SYSTEM ADMINISTRATORS role to access all reconciliation management actions See Also: Managing Scheduled Tasks in the Oracle Fusion Middleware Administrators Guide for Oracle Identity Manager for information about the Scheduler feature 15-26 Oracle Fusion Middleware Users Guide for Oracle Identity Manager – Job Modify – Job pause – Job Resume – Job run now – Job Search – Job stop – Reset Status – Scheduler Search – Scheduler Start – Scheduler Stop – Trigger Create – Trigger Delete – Trigger Modify These permissions do not support fine-grained attribute-level controls. ■ Data security: None ■ Description: Allows users with the SYSTEM ADMINISTRATORS or SCHEDULER ADMINISTRATORS role to access all scheduler actions.

15.3.8 Request Template Management

Any user with the REQUEST TEMPLATE ADMINISTRATORS role has access to all management operations related to request templates, such as creating, deleting, modifying, and searching request templates. For information about the default authorization policy, see Request Creation By Using Request Templates on page 15-26.

15.3.9 Request Creation By Using Request Templates

Each request template can be associated with a set of roles. Only the users with any of these roles are able to create a request by using this template. When a new request template is created with a list of associated roles, a new authorization policy is created internally. In addition, if the role association with any of the existing request templates is modified adding new roles or removing existing roles, then the existing authorization policy for this template is modified. The default authorization policy for creating requests by using request template allows users with the REQUEST TEMPLATES ADMINISTRATORS role to access all operations related to request templates. The policy has the following details: ■ Policy name: Request Template Administration Policy ■ Assignee: REQUEST TEMPLATE ADMINISTRATORS role ■ Functional security: The permissions are: – Create See Also: Chapter 17, Managing Request Templates for information about creating and managing request templates for request creation