Data Security Default Authorization Policy

15-28 Oracle Fusion Middleware Users Guide for Oracle Identity Manager – Delete – Filter – Lookup – Modify – Remove Locale – Search These permissions do not support fine-grained attribute-level controls. ■ Data security: None ■ Description: Allows users with SYSTEM ADMINISTRATORS or NOTIFICATION TEMPLATE ADMINISTRATORS role to access all notification template management actions.

15.3.12 System Properties

The default authorization policy for the system properties feature allows users with the System Administrators and SYSTEM CONFIGURATION ADMINISTRATORS roles to access all operations related to system properties. This policy has the following details: ■ Policy name: System Properties Administration Policy ■ Assignee: System Administrators and SYSTEM CONFIGURATION ADMINISTRATORS roles ■ Functional security: The permissions include: – Create – Delete – Filter – Lookup – Modify – Search These permissions do not support fine-grained attribute-level controls. ■ Data Constraints: None ■ Description: Allows users with the SYSTEM ADMINISTRATORS or SYSTEM CONFIGURATION ADMINISTRATORS role to access all system properties actions

15.3.13 Diagnostic Dashboard

The default authorization policy for the Diagnostic Dashboard feature allows users with the System Administrators role to access the diagnostic dashboard. This policy has the following details: See Also: Administering System Properties in the Oracle Fusion Middleware Administrators Guide for Oracle Identity Manager for information about the system properties Managing Authorization Policies 15-29 ■ Policy name: Diagnostic Dashboard Policy ■ Assignee: System Administrators role ■ Functional security: The Manage Failed Tasks permission without any fine-grained attribute-level controls ■ Data constraints: None ■ Description: Allows users with the SYSTEM ADMINISTRATORS role to access the Diagnostic Dashboard

15.3.14 Plug In

The default authorization policy for the Plug In feature allows users with the PLUGIN ADMINISTRATOR role to register unregistered policies. This policy has the following details: ■ Policy name: Plugin Administrator Policy ■ Assignee: PLUGIN ADMINISTRATOR and SYSTEM ADMINISTRATOR role ■ Functional security: The permissions are: – Register Plug In – Unregister Plug In These permissions do not support fine-grained attribute-level controls. ■ Data constraints: None ■ Description: Allows users with the PLUGIN ADMINISTRATORS or SYSTEM ADMINISTRATORS role to register and unregister plugins See Also: Working With the Diagnostic Dashboard in the Oracle Fusion Middleware Administrators Guide for Oracle Identity Manager for information about the Diagnostic Dashboard See Also: Developing Plug-ins in the Oracle Fusion Middleware Developers Guide for Oracle Identity Manager for information about plug-ins