Use the Scope tab to assign accounts, account groups, assets, and asset groups to an access request policy.
Navigate to:
- desktop client: Administrative Tools | Entitlements | Access Request Policies | (create or edit a policy)
- On the Scope tab:
-
Click Add from the details toolbar and select one of the following options:
- Add Account Group
- Add Account
- Add Asset Group: Only available for a session access request (that is, when access type RDP, SSH, or Telnet is selected on the General tab.
-
Add Asset: Only available for a session access request (that is, when access type RDP, SSH, or Telnet is selected on the General tab.
NOTE: When scoped to an asset, the target account is determined by the Asset-Based Session Access settings on the Access Config tab (create access request policy desktop client).
-
In the dialog, make a selection then click OK.
If you do not see the selection you are looking for, depending on your Administrator permissions, you can create it in the dialog. (You must have Asset Administrator permissions to create accounts and assets. You must have Security Policy Administrator permissions to create account groups and asset groups.)
-
-
Repeat step one to make additional selections. You can add multiple types of objects to a policy; however, you can only add one type of object, like an accounts or account group, at a time.
All of the selected objects appear on the Scope tab in the Access Request Policy dialog. To remove an object from the list, select the object and click Delete.