Authorization Policy Oracle Fusion Middleware Online Documentation Library

Managing Authorization Policies 15-5 5. In the Entity Type field, select the entity type for whom the authorization policies are defined.

6. Click Search. The search results are displayed in the search results table, as shown

in Figure 15–2 : Figure 15–2 Authorization Policy Advanced Search

15.2.2 Creating Custom Authorization Policies

Oracle Identity Manager Administration allows you to create custom authorization policies for the following Oracle Identity Manager components: ■ User Management ■ Role Management ■ Authenticated Self Service User Management This section describes authorization policy creation in the following topics: ■ Creating an Authorization Policy for User Management ■ Creating an Authorization Policy for Role Management ■ Creating an Authorization Policy for Authenticated User Self Service

15.2.2.1 Creating an Authorization Policy for User Management

You can create custom authorization policies for user management to control access to user management operations. For example, you can specify that the users belonging to a particular role can search for all users or users belonging to a specific organization, and view a set of selected user attributes. To create an authorization policy for user management:

1. Login to the Administrative and User Console, and click Administration.

15-6 Oracle Fusion Middleware Users Guide for Oracle Identity Manager

2. On the Welcome page, under Authorization Policies, click Create Authorization

Policy . Alternatively, you can click the Authorization Policy tab, and then click the Create Authorization Policy icon on the toolbar, or select Create from the Actions menu. The Basic Policy Information page of the Create Policy wizard is displayed, as shown in Figure 15–3 : Figure 15–3 The Basic Policy Information Page 3. In the Policy Name field, enter the name of the authorization policy. 4. In the Description field, enter a description of the authorization policy. 5. To create an authorization policy for user management, in the Entity name field, select User Management.

6. Click Next. The Permissions page is displayed, as shown in

Figure 15–4 : Note: You must be a member of the System Administrators role to create, modify, delete, search authorization policies. Note: In the Basic Policy Information page of the Create Policy wizard, only the Basic Policy Information, Policy Settings and Confirmation Nodes are shown at the top of the page. The other Nodes of the wizard are dynamically generated based on your selection in the Entity Name field.