You can choose to modify which Policy Objects are linked to the selected directory object. This only modifies links on the selected directory object, and not the entire policy scope.
To view or modify a list of Policy Objects on a specific directory object
- Open the Active Roles Policy dialog for the object in one of the following ways:
-
In the Console tree, right-click the directory object that you want to add policies to, then click Enforce Policy.
-
In the Console tree, right-click the directory object that you want to add policies to, then click Properties. Then, on the Administration tab in the Properties dialog, click Policy.
-
In the Active Roles Policy dialog, choose which action you want to perform:
-
To define additional policy settings on the object, click Add, then select one or more Policy Objects, and click OK.
-
To block a linked Policy Object on the directory object, select Blocked next to the name of the Policy Object. To reapply the Policy Object, clear Blocked next to the name of the Policy Object.
-
To remove a Policy Object link from the directory object, select the Policy Object and click Remove.
NOTE: You can only perform this operation if the Policy Object is linked to the directory object itself, not to a container or Managed Unit that is the parent of the object.
-
To view or modify policies in a Policy Object, select the Policy Object that you want to modify, and click View/Edit. For more information, see Modifying policies in a Policy Object.
-
To display a list of the Policy Object links, click Advanced. For more information on advanced policy settings, see Managing advanced Policy Object link settings.
-
To apply your changes and close the Active Roles Policy dialog, click OK.
You can choose to modify which Policy Objects are linked to the selected directory object. This only modifies links on the selected directory object, and not the entire policy scope.
To view or modify Policy Object links that determine the policy settings on a specific directory object
- Open the Active Roles Policy dialog for the object in one of the following ways:
-
In the Console tree, right-click the directory object that you want to add policies to, then click Enforce Policy.
-
In the Console tree, right-click the directory object that you want to add policies to, then click Properties. Then, on the Administration tab in the Properties dialog, click Policy.
-
Click Advanced.
-
In the Active Roles Policy - Advanced View dialog, choose which action you want to perform:
-
To create a new link, click Add, and then select the Policy Object that you want.
-
To remove a link, select it from the list and click Remove.
NOTE: You can only perform this operation if the Policy Object is linked to the directory object itself, not to a container or Managed Unit that is the parent of the object.
-
To view or modify policies in a Policy Object, select the Policy Object that you want to modify, and click View/Edit.
-
To specify whether a link removes or applies the Policy Object on the selected directory object, select the link and and to toggle the Include/Exclude setting, click Include or Exclude, respectively.
NOTE: By default, the Advanced View dialog lists all the links that determine the policy settings on the object, and whether a link was created on the object itself or on a parent container or Managed Unit. To display the policy settings only on the selected object, clear Show inherited.
You can create copies of existing Policy Objects using Active Roles Console.
To copy a Policy Object
-
In the Console tree, navigate to Configuration > Policies > Administration.
-
Select the folder that contains the Policy Object that you want to copy.
-
To start the Copy Object - Policy Object Wizard, in the details pane, right-click the Policy Object, then click Copy.
-
On the Name and Description page, provide a unique Name for the new Policy Object. Optionally, also provide a Description. To continue, click Next.
-
(Optional) To open the Properties dialog after you finish copying the Policy Object, select Display the object properties when this wizard closes.
You can view or modify policies in the Properties dialog of the newly created Policy Object.
- Click Finish.
For more information on adding, modifying, removing and blocking policies in a Policy Object, see the following sections:
You can rename existing Policy Objects using Active Roles Console.
NOTE: You can only delete or rename Policy Objects that you have created. Built-in Policy Objects can only be copied or exported.
To rename a Policy Object
-
In the Console tree, navigate to Configuration > Policies > Administration.
-
Select the folder that contains the Policy Object that you want to rename.
-
In the details pane, right-click the Policy Object, then click Rename.
-
Type a new name, then press Enter.
NOTE: Renaming the Policy Object does not cause any changes to the policy settings in the directory. This is because Active Roles identifies the Policy Object by an internal identifier.