Authorization for Resource Requests

15-22 Oracle Fusion Middleware Users Guide for Oracle Identity Manager

15.3.4 Authorization Policy Management

Access to the authorization policy management feature is controlled by a default authorization policy. This policy grants the users who belong to the System Administrators role to perform authorization policy operations, such as searching Role Management Role Owner Policy ALL USERS role The permissions are: Delete Role Modify Role Modify Role Hierarchy Modify Role Membership Search for Role Search for Role Categories View Role Category Detail View Role Detail View Role Membership All Roles that the assignee is the owner of. When a user creates a role, the person with the role created will become the role owner. This is the predefined authorization policy to enable role owners to have control of their roles. Role Management Approval and Request Policy APPROVAL POLICY ADMINISTRA TORS, REQUEST TEMPLATE ADMINISTRA TORS roles, and REQUEST ADMINISTRA TORS roles The permissions are: Search for Role Search for Role Categories View Role Category Detail View Role Detail All Roles This is the predefined authorization policy associated with the APPROVAL POLICY ADMINISTRATORS, REQUEST ADMINISTRATORS, and REQUEST TEMPLATE ADMINISTRATORS roles. Role Management Delegated Administration Policy ROLE ADMINISTRA TORS role The permissions are: Modify Role Membership Search for Role Search for Role Categories View Role Category Detail View Role Detail View Role Membership All Roles This policy can be used as an example for the Delegated Role Administrator persona. You can change the assignee and the data constraint, if required. Role Management Hierarchy Administration Policy ROLE ADMINISTRA TORS role The permissions are: Modify Role Modify Role Hierarchy Search for Role Search for Role Categories View Role Category Detail View Role Detail View Role Membership All Roles This policy can be used as an example for the Role Hierarchy Administrator persona. You can change the assignee and the data constraint, if required. Policy Name Assignee Functional Security Data Security Description Managing Authorization Policies 15-23 authorization policies, and creating, modifying, and deleting custom authorization policies. The details of the default authorization policy for this feature is the following: ■ Policy Name: Authorization Management Administration Policy ■ Assignee: System Administrators role ■ Functional security: The supported permissions are: – Create Authorization Policies – Delete Authorization Policies – Modify Authorization Policies – Search Authorization Policies These privileges do not support fine-grained attribute-level controls. ■ Data security: This authorization policy does not support any data security. Anybody with the privileges to manage authorization policies can manage any and all authorization policies.

15.3.5 User Management Configuration

The default authorization policy for the user management configuration feature allows users with the System Administrators and USER CONFIGURATION ADMINISTRATORS roles to access all user management configuration operations. This policy has the following details: ■ Policy name: User Management Configuration Administration Policy ■ Assignee: System Administrators and USER CONFIGURATION ADMINISTRATORS roles ■ Functional security: The permissions are: – Add Category – Add Derived Attributes – Create Attribute – Delete Attribute – Delete Category – Set Search Attributes – Set Search Attributes Note: The delete or disable action is controlled by feature-specific UI code, which calls AuthorizationService API to find out whether the user is allowed to perform that action. If the user has the permission, then under Action list on the left pane of the UI, the user can see Delete or Disable options enabled. See Also: Configuring User Attributes in the Oracle Fusion Middleware Administrators Guide for Oracle Identity Manager for information about the user management configuration feature