Access Policy Priority Features of Access Policies

16-8 Oracle Fusion Middleware Users Guide for Oracle Identity Manager

6. Click Continue.

The Create Access Policy - Step 2: Select Resources to provision page is displayed. 7. Specify the resource to be provisioned for this access policy. Search for resources by using the filter search menu. ■ Select the name of the resource from the results table, and then click Add. ■ The names of the desired resources to provision appear in the Selected list. If you want to create an access policy that only denies resources, click Continue without selecting a resource. ■ To unassign the selected resources, highlight the resource in the Selected list and click Remove.

8. Click Continue.

If there is a form associated with this resource, the subsequent pages display the required fields. Otherwise, the Create Access Policy - Step 2: Select Resources to Revoke page is displayed. It is recommended that you do not specify policy defaults for passwords and encrypted attributes. 9. Specify whether or not access policies are to be revoked if they no longer apply. Select the check boxes for the resources you want to revoke automatically from the results table.

10. Click Continue.

The Create Access Policy - Step 3: Selected Resources to deny page is displayed. 11. Use this page to select resources to be denied by this access policy. To select resources to be denied: a. Select the resources from the results table.

b. Click Add to place the resource in the Selected list.

You must select at least one resource to deny if you have not selected any resources to be provisioned. Selecting the same resources to be denied as to be provisioned will automatically unassign them from the resources to be provisioned selection. Similarly, in Step a, assigning the same resources to be provisioned as you have already selected to be denied will automatically remove them from the resources to be denied selection. You can remove the resources that were selected to be denied. You do this by selecting those resources from the Selected list, and clicking Remove. c. Click Continue. The Create Access Policy - Step 4: Select Roles page is displayed. 12. Use the Create Access Policy - Step 4: Select Group page to associate a group with the access policy. 13. To associate a role with this access policy: ■ Select the role from the results table, and then click Add. You must select at least one role. The names of the selected roles appear in the Selected list. ■ You can delete the role name by clicking Remove. 14. Click Continue. Managing Access Policies 16-9 The Create Access Policy - Step 5: Verify Access Policy Information page is displayed. 15. If you want to modify any of the selections you made in the preceding steps of this procedure, then click Change to go to the corresponding page of the wizard. After making the required modifications, click Continue to return to the Step 5: Verify Access Policy Information page.

16. Click Create Access Policy to create the access policy.

16.4 Managing Access Policies

You can use Oracle Identity Manager Administrative and User Console to modify information in existing access policies. To manage access policies:

1. Click Manage Access Policies under the Policies menu.

The Manage Access Policies page is displayed. Use the menu in the search criteria field to select an access policy attribute. You can use the asterisk wildcard character to search for all access policy instances that have any value for the attribute selected. Click Search Access Policies. The Manage Access Policies page is displayed with your search results.

2. To view the details of the Access Policy you want, click Access Policy Name.

The Access Policy Details page is displayed. To make modifications to this access policy, use the Change link at the end of each selection category.

3. After you make the required modifications, click Update Access Policy.

This access policy is updated, and the updated information is displayed on the Access Policy Details page.

16.5 Provisioning Multiple Instances of the Same Resource via Access Policy

Provisioning multiple instances of the same resource via access policy by using account discriminator involves the following: ■ Creating Separate Accounts for the Same User and Same Resource on a Single Target System ■ Enabling Multiple Account Provisioning ■ Provisioning Multiple Instances of a Resource to Multiple Target Systems ■ Limitation of Provisioning Multiple Instances of a Resource via Access Policy Note: When you create an access policy on a resource having a process form with Password field, the password policy is not evaluated. For information about password policies, see Oracle Fusion Middleware Administrators Guide for Oracle Identity Manager.