Click Save. The selected organizations are added in the table in the Data

15-12 Oracle Fusion Middleware Users Guide for Oracle Identity Manager 7. You can modify some permissions that have attribute-level settings. To do so:

a. Select the permission, for example, Modify User Profile, and click Edit

Attributes on the toolbar. The Attribute Settings window is displayed with a list of all user attributes.

b. Select the attributes that you want to allow the user to modify, and click Save.

8. Click Next. The Policy Assignment page is displayed with a table that contains the

roles that are assigned to this policy.

9. To add a role to the policy, click Add. Alternatively, from the Actions menu, select

Add . The Assign Roles window is displayed. 10. Search for role in the Assign Roles window, select the role or roles that you want to assign to the policy, and click Add. The role is added to the policy assignment table. The authorization Policy will be enabled for all the members of the assigned roles. To remove a role from the policy, select the role in the policy assignment table, and click Remove. 11. Click Next. The Confirmation page is displayed with Basic Policy Information and details about permissions, data constraints, and assignments.

12. Click Finish. The authorization policy is created.

15.2.3 Creating Authorization Policies Based on Existing Policies

You can create an authorization policy by using the general, permissions, data constraints, and assignment information from another authorization policy already existing in Oracle Identity Manager. To do so: 1. Search for the authorization policy from which you want to use information to create another policy.

2. Select the policy. From the Actions menu, select Create Like. The Authorization

Policy wizard is displayed. 3. In the Basic Policy Information page, edit the Policy Name, Description, and Entity Name fields to specify new values. 4. Perform the steps to complete the wizard as described in Creating Custom Authorization Policies on page 15-5.

15.2.4 Viewing and Modifying Authorization Policies

You can view and modify authorization policies, and change the general information, permissions, data constraints, and assignments of the authorization policies. To do so: 1. In the Authorization Policy tab of the Administration Console, in the left pane, search for authorization policies. The policies matching the search criteria are displayed in the search results table. Note: The options for authorization policy modification changes dynamically based on the entity type selected for the policy. In this procedure, the example of an authorization policy for role management is used. Managing Authorization Policies 15-13 2. Click an authorization policy. Alternatively, you can select an authorization policy, and from the Actions menu, select Open. The page that allows you to view and modify authorization policy details is displayed. The General tab of the page is displayed by default, with details about the policy name, description, entity name, permissions, data constraints, and assignment. 3. Edit the Policy Name and Description fields to update the authorization policy name and description.

4. Click the Permissions tab. In this tab, you can check the permissions that you

want to enable in this policy. To do so, select the permissions from the table, or select Enable All Permissions to enable all permissions. Some permissions have attribute-level settings. To modify the attribute-level settings, click Edit Attributes.

5. Click the Data Constraints tab. In this tab, you can modify the roles that the user

must be a member of for this authorization policy. 6. Select any one of the following options: ■ All Roles: To specify that the authorization policy is applicable to all roles in Oracle Identity Manager including all the child roles. ■ Selected Roles: To specify that the authorization policy is applicable to selected roles only. 7. If you select the Selected Roles option, then you must select the roles for which the authorization policy is been created. This tab also allows you to remove selected roles. To add or remove roles, perform the steps described in steps 10 or 11 respectively of Creating an Authorization Policy for Role Management on page 15-9.

8. Select Hierarchy Aware include all Parent Roles to specify that all the parent

roles of the selected roles must be selected for the authorization.

9. Click the Assignment tab. This tab displays the roles that are assigned to this

policy. You can add or remove the assignment by performing steps 10 or 11 respectively of Creating Custom Authorization Policies on page 15-5 and Creating an Authorization Policy for Role Management on page 15-9.

10. Click Apply to save changes.

Alternatively, click Revert to refresh the page with old values. Note: You cannot change the entity name of an authorization policy after the policy is created. Note: Steps 6 through 8 are applicable for authorizations policies for roles. See Also: Disabling Access to Features Through the Authorization Policies in the Oracle Fusion Middleware Developers Guide for Oracle Identity Manager for information about disabling or hiding features by using authorization policies