My Oracle Support Banner

How to create custom role which inherits an out-of-the-box role and then an authorization policy is applied to the custom role to permssions are scaled down ? (Doc ID 1418013.1)

Last updated on JANUARY 31, 2022

Applies to:

Identity Manager - Version 11.1.1.3.1 and later
Information in this document applies to any platform.

Goal


Created a custom role in OIM and had it inherit the out-of-the-box (say IDENTITY USER ADMINISTRATORS) role. Then I applied an OIM authorization policy to the custom role to scale back the permissions for that role. However, the authorization policy does not seem to override the permissions granted by the inherited IDENTITY USER ADMINISTRATORS role. Is this the expected behavior?

Replication Steps on the question:
Create an Org say XYZ Org
Create an User - ABC with XYZ Org as its Organization
Create Role - XYZ Role, inheriting Identity User Admin Role
   - Leave the Role Category set to default and Owner to System Admin
Create Auth policy - XYZ Auth Policy
   * include XYZ Role in this Auth policy.
Assign the Role - XYZ Role to user - ABC
Login as ABC to OIM Admin Console.
You see the below behavior:
  - permissions that are not included in XYZ Auth Policy like disable user, unlock user, delete user are displayed.

Solution

To view full details, sign in with your My Oracle Support account.

Don't have a My Oracle Support account? Click to get started!


My Oracle Support provides customers with access to over a million knowledge articles and a vibrant support community of peers and Oracle experts.