If you want to remove Policy Object links from directory objects, use the Policy Scope dialog of Active Roles Console.
To remove Policy Object links
-
In the Console tree, navigate to Configuration > Policies > Administration.
-
Select the folder that contains the Policy Object that you want to remove.
-
In the details pane, right-click the Policy Object, then click Policy Scope.
-
In the Active Roles Policy Scope dialog, select the object, and click Remove.
-
To apply your changes and close the Active Roles Policy dialog, click OK.
For more information on managing Policy Object links, see Managing Policy Object links.
If you want to view or modify the properties of a link, such as the inheritance options, use the Policy Scope dialog of Active Roles Console.
To view or modify Policy Object links
-
In the Console tree, navigate to Configuration > Policies > Administration.
-
Select the folder that contains the Policy Object that you want to modify.
-
In the details pane, right-click the Policy Object, then click Policy Scope.
-
In the Active Roles Policy Scope dialog, select the object, and click View/Edit.
-
To apply your changes and close the Active Roles Policy dialog, click OK.
For more information on managing Policy Object links, see Managing Policy Object links.
Link Policy Objects to enforce business rules on different types of directory objects in the Active Roles Console. These objects are the following:
-
Administrative views (Active Roles Managed Units).
-
Active Directory containers (Organizational Units).
-
Individual (leaf) directory objects, such as user or group objects.
To view or modify inheritance options for a Policy Object on a container or Managed Unit
-
Right-click the Policy Object, then click Policy Scope.
-
In the Active Roles Policy Scope dialog, select the container or Managed Unit that you want to examine inheritance options for, and click View/Edit.
-
On the General tab, view or modify the following options:
-
This directory object: The scope includes the container or Managed Unit you have selected. This option does not cause the scope to include any child objects or members of the container or Managed Unit.
-
Child objects of this directory object: The scope includes all child objects or members in the hierarchy under the selected container or Managed Unit.
-
Immediate child objects only: The scope includes only the first level of child objects or members that are under the selected container or Managed Unit.
If you want to specify whether a link removes or applies the Policy Object on the directory object to which the Policy Object is linked, use the Policy Scope dialog of Active Roles Console.
To include or exclude directory objects from the policy scope
-
In the Console tree, navigate to Configuration > Policies > Administration.
-
Select the folder that contains the Policy Object that you want to modify.
-
In the details pane, right-click the Policy Object, then click Policy Scope.
-
In the Active Roles Policy Scope dialog, select the object, and to toggle the Include/Exclude setting, click Include or Exclude, respectively.
-
To apply your changes and close the Active Roles Policy dialog, click OK.
NOTE: Excluding an object from the policy scope creates a Policy Object link on that object, and it will be flagged as Exclude Explicitly. Restoring the Policy Object will remove that link.
For more information on managing Policy Object links, see Managing Policy Object links.