Assignee Functional Security Data Security

15-24 Oracle Fusion Middleware Users Guide for Oracle Identity Manager – Update Attribute – Update Category These permissions do not support fine-grained attribute-level controls. ■ Data security: None ■ Description: This policy allows users with the SYSTEM ADMINISTRATORS or USER CONFIGURATION ADMINISTRATORS roles to access all user management configuration actions.

15.3.6 Reconciliation Management

The components of the authorization policies defined for the reconciliation management feature and the default authorization policy for this feature are described in the following sections: ■ Assignee ■ Functional Security ■ Data Security ■ Default Authorization Policy

15.3.6.1 Assignee

The assignee of the policy can be a role or a set of roles.

15.3.6.2 Functional Security

The reconciliation management feature defines multiple privileges from the authorization policy management area. These privileges do not support fine-grained attribute-level controls.

15.3.6.3 Data Security

This authorization policy does not support any data security. A user with the privileges to manage reconciliation events can manage all reconciliation events.

15.3.6.4 Default Authorization Policy

The following table lists the default authorization policies for the reconciliation management feature: Note: When the user is authorized to view all attributes on the pages to create and modify users, if an UDF is created through User Management Configuration, then the UDF is displayed in the pages to create and modify users. See Also: Managing Reconciliation Events in the Oracle Fusion Middleware Administrators Guide for Oracle Identity Manager and Chapter 4, Deployment Configurations for information about the reconciliation feature Managing Authorization Policies 15-25

15.3.7 Scheduler

The default authorization policy for the scheduler feature allows users with the System Administrators and SCHEDULER ADMINISTRATOR roles to access all scheduler operations. This policy has the following details: ■ Policy Name: Scheduler Administration Policy ■ Assignee: System Administrators and SCHEDULER ADMINISTRATOR roles ■ Functional security: The permissions are: – Job Create – Job Delete – Job Disable – Job Enable – Job Filter Policy Name Assignee Functional Security Data Security Description Reconciliation Management Administration Policy SYSTEM ADMINISTRATORS and RECONCILIATION ADMINISTRATORS roles The permissions include: Assign Bulk Action Create Act Create User Link Act Link User Search View Event Details These permissions do not support fine-grained attribute-level controls. None Allows users with the RECONCILIATION ADMINISTRATORS or SYSTEM ADMINISTRATORS role to access all reconciliation management actions Reconciliation API Policy SYSTEM ADMINISTRATORS and RECONCILIATION ADMINISTRATORS roles The permissions are: Create Reconciliation Event Delete detected Accounts Get Missing Accounts Ignore Event Link Event to Resource for user Link Event to User Process Reconciliation Event These permissions do not support fine-grained attribute-level controls. None Allows users with the RECONCILIATION ADMINISTRATORS or SYSTEM ADMINISTRATORS role to access all reconciliation management actions See Also: Managing Scheduled Tasks in the Oracle Fusion Middleware Administrators Guide for Oracle Identity Manager for information about the Scheduler feature