立即与支持人员聊天
与支持团队交流

Active Roles 8.2.1 - Administration Guide

Introduction Getting started with Active Roles Configuring rule-based administrative views Configuring role-based administration Configuring rule-based autoprovisioning and deprovisioning
Configuring Provisioning Policy Objects
User Logon Name Generation E-mail Alias Generation Exchange Mailbox AutoProvisioning Group Membership AutoProvisioning Home Folder AutoProvisioning Property Generation and Validation Script Execution O365 and Azure Tenant Selection AutoProvisioning in SaaS products
Configuring Deprovisioning Policy Objects
User Account Deprovisioning Group Membership Removal User Account Relocation Exchange Mailbox Deprovisioning Home Folder Deprovisioning User Account Permanent Deletion Office 365 Licenses Retention Group Object Deprovisioning Group Object Relocation Group Object Permanent Deletion Script Execution Notification Distribution Report Distribution
Configuring entry types Configuring a Container Deletion Prevention policy Configuring picture management rules Managing Policy Objects Checking for policy compliance Deprovisioning users or groups Restoring deprovisioned users or groups Configuring policy extensions
Using rule-based and role-based tools for granular administration Workflows
About workflow processes Workflow processing overview Workflow activities overview Configuring a workflow
Creating a workflow definition for a workflow Configuring workflow start conditions Configuring workflow parameters Adding activities to a workflow Configuring an Approval activity Configuring a Notification activity Configuring a Script activity Configuring an If-Else activity Configuring a Stop/Break activity Configuring an Add Report Section activity Configuring a Search activity Configuring CRUD activities Configuring a Save Object Properties activity Configuring a Modify Requested Changes activity Enabling or disabling an activity Enabling or disabling a workflow Using the initialization script
Approval workflow Email-based approval Automation workflow Activity extensions
Temporal Group Memberships Group Family Dynamic groups Active Roles Reporting Management History Entitlement profile Recycle Bin AD LDS data management One Identity Starling Join and configuration through Active Roles Managing One Identity Starling Connect Configuring linked mailboxes with Exchange Resource Forest Management Configuring remote mailboxes for on-premises users Migrating Active Roles configuration with the Configuration Transfer Wizard Managing Skype for Business Server with Active Roles
About Skype for Business Server User Management Active Directory topologies supported by Skype for Business Server User Management User Management policy for Skype for Business Server User Management Master Account Management policy for Skype for Business Server User Management Access Templates for Skype for Business Server Configuring the Skype for Business Server User Management feature Managing Skype for Business Server users
Exchanging provisioning information with Active Roles SPML Provider Monitoring Active Roles with Management Pack for SCOM Configuring Active Roles for AWS Managed Microsoft AD Azure AD, Microsoft 365, and Exchange Online Management
Azure tenant types and environment types supported by Active Roles Using Active Roles to manage Azure AD objects Unified provisioning policy for Azure M365 Tenant Selection, Microsoft 365 License Selection, Microsoft 365 Roles Selection, and OneDrive provisioning Changes to Active Roles policies for cloud-only Azure objects
Managing the configuration of Active Roles
Connecting to the Administration Service Managed domains Using unmanaged domains Evaluating product usage Creating and using virtual attributes Examining client sessions Monitoring performance Customizing the Console Using Configuration Center Changing the Active Roles Admin account Enabling or disabling diagnostic logs Active Roles Log Viewer
SQL Server replication Using regular expressions Administrative Template Configuring federated authentication Communication ports and URLs used by Active Roles Integrating Active Roles with other products and services Active Roles Language Pack Active Roles Diagnostic Tools Active Roles Add-on Manager

Managing linked Policy Objects on a directory object

You can choose to modify which Policy Objects are linked to the selected directory object. This only modifies links on the selected directory object, and not the entire policy scope.

To view or modify a list of Policy Objects on a specific directory object

  1. Open the Active Roles Policy dialog for the object in one of the following ways:
    • In the Console tree, right-click the directory object that you want to add policies to, then click Enforce Policy.

    • In the Console tree, right-click the directory object that you want to add policies to, then click Properties. Then, on the Administration tab in the Properties dialog, click Policy.

  2. In the Active Roles Policy dialog, choose which action you want to perform:

    • To define additional policy settings on the object, click Add, then select one or more Policy Objects, and click OK.

    • To block a linked Policy Object on the directory object, select Blocked next to the name of the Policy Object. To reapply the Policy Object, clear Blocked next to the name of the Policy Object.

    • To remove a Policy Object link from the directory object, select the Policy Object and click Remove.

      NOTE: You can only perform this operation if the Policy Object is linked to the directory object itself, not to a container or Managed Unit that is the parent of the object.

    • To view or modify policies in a Policy Object, select the Policy Object that you want to modify, and click View/Edit. For more information, see Modifying policies in a Policy Object.

    • To display a list of the Policy Object links, click Advanced. For more information on advanced policy settings, see Managing advanced Policy Object link settings.

  3. To apply your changes and close the Active Roles Policy dialog, click OK.

Managing advanced Policy Object link settings

You can choose to modify which Policy Objects are linked to the selected directory object. This only modifies links on the selected directory object, and not the entire policy scope.

To view or modify Policy Object links that determine the policy settings on a specific directory object

  1. Open the Active Roles Policy dialog for the object in one of the following ways:
    • In the Console tree, right-click the directory object that you want to add policies to, then click Enforce Policy.

    • In the Console tree, right-click the directory object that you want to add policies to, then click Properties. Then, on the Administration tab in the Properties dialog, click Policy.

  2. Click Advanced.

  3. In the Active Roles Policy - Advanced View dialog, choose which action you want to perform:

    • To create a new link, click Add, and then select the Policy Object that you want.

    • To remove a link, select it from the list and click Remove.

      NOTE: You can only perform this operation if the Policy Object is linked to the directory object itself, not to a container or Managed Unit that is the parent of the object.

    • To view or modify policies in a Policy Object, select the Policy Object that you want to modify, and click View/Edit.

    • To specify whether a link removes or applies the Policy Object on the selected directory object, select the link and and to toggle the Include/Exclude setting, click Include or Exclude, respectively.

NOTE: By default, the Advanced View dialog lists all the links that determine the policy settings on the object, and whether a link was created on the object itself or on a parent container or Managed Unit. To display the policy settings only on the selected object, clear Show inherited.

Copying a Policy Object

You can create copies of existing Policy Objects using Active Roles Console.

To copy a Policy Object

  1. In the Console tree, navigate to Configuration > Policies > Administration.

  2. Select the folder that contains the Policy Object that you want to copy.

  3. To start the Copy Object - Policy Object Wizard, in the details pane, right-click the Policy Object, then click Copy.

  4. On the Name and Description page, provide a unique Name for the new Policy Object. Optionally, also provide a Description. To continue, click Next.

  5. (Optional) To open the Properties dialog after you finish copying the Policy Object, select Display the object properties when this wizard closes.

    You can view or modify policies in the Properties dialog of the newly created Policy Object.

  6. Click Finish.

For more information on adding, modifying, removing and blocking policies in a Policy Object, see the following sections:

Renaming a Policy Object

You can rename existing Policy Objects using Active Roles Console.

NOTE: You can only delete or rename Policy Objects that you have created. Built-in Policy Objects can only be copied or exported.

To rename a Policy Object

  1. In the Console tree, navigate to Configuration > Policies > Administration.

  2. Select the folder that contains the Policy Object that you want to rename.

  3. In the details pane, right-click the Policy Object, then click Rename.

  4. Type a new name, then press Enter.

NOTE: Renaming the Policy Object does not cause any changes to the policy settings in the directory. This is because Active Roles identifies the Policy Object by an internal identifier.

相关文档

The document was helpful.

选择评级

I easily found the information I needed.

选择评级