The objects on which a given Policy Object has effect are collectively referred to as the policy scope of the Policy Object. When applying a Policy Object, you add objects to the policy scope. You can use the following instructions to exclude certain objects from the policy scope of a Policy Object, in order to remove the effect of the Policy Object on those objects.
To exclude an object from the policy scope of a Policy Object
- Open the Active Roles Policy dialog box for the object:
- Right-click the object, and click Enforce Policy.
- Right-click the object, and click Properties. Then, on the Administration tab in the Properties dialog box, click Policy.
- In the Active Roles Policy dialog box, select the Blocked check box next to the name of the Policy Object.
- Click OK to close the Active Roles Policy dialog box.
|
NOTE:
- You can restore the effect of the Policy Object on the object that was excluded from the policy scope: In the Active Roles Policy dialog box for that object, clear the Blocked check box next to the name of the Policy Object.
- Excluding an object from the policy scope creates a Policy Object link on that object, the link being flagged Exclude Explicitly. Restoring the effect of the Policy Object causes that link to be removed. For instructions on how to manage Policy Object links, see Steps for managing Policy Object links earlier in this document.
|
With the Active Roles console, you can create copies of Policy Objects. This feature helps you re-use existing Policy Objects.
To create a copy of a Policy Object, right-click the Policy Object, and click Copy. This opens the Copy Object wizard. Type a name and description for the copy, and then click Next.
On the next page, the wizard displays a list of policies. The list includes all policies defined in the original Policy Object. Click Finish to create the copy.
The copy has the same properties as the original Policy Object, including the policies and their configurations. You can make changes to the copy using the Properties dialog box, as described earlier in this chapter (see Adding, modifying, or removing policies).
To rename a Policy Object, right-click the Policy Object, and click Rename. Type the new name, and then press ENTER. Renaming a Policy Object does not affect its links. This is because Policy Objects are referenced by immutable identifier rather than by name.