Access policies
A policy is a set of settings of base components, integration modules, business applications, and accounts that can be applied to a specific selection of users from the user catalog. All users included in the policy receive accounts for applications with the corresponding settings, or the settings themselves from the policy.
A policy can define the following:
- The scope: the users who fall under the rules specified in this policy.
- The roles: administrator, operator, and inspector.
- The set and settings of the available authentication methods.
- The set of available business applications and their role accounts.
- The policy priority.
If a user falls within the scope of more than one policy, they get access to all applications added to these policies.
If the same application occurs more than once in the policies whose scope the user falls into, the user is assigned the access settings for this application from the policy with the highest priority.
For example, if policy #1 specifies the use of SMS OTP for ADFS Extension, and the higher-priority policy #2 specifies the use of Email OTP for ADFS Extension, the user must log in through ADFS using Email OTP.
If the policy with the highest priority has no settings for the application, the settings from the next policy by priority are used.
In ESSO scenarios, there may be exceptions related to the implementation specifics of ESSO Agent.