How to create custom role which inherits an out-of-the-box role and then an authorization policy is applied to the custom role to permssions are scaled down ?

(Doc ID 1418013.1)

Last updated on DECEMBER 02, 2016

Applies to:

Identity Manager - Version and later
Information in this document applies to any platform.
**Checked for Relevance on 27-Sep-2013**


Created a custom role in OIM and had it inherit the out-of-the-box (say IDENTITY USER ADMINISTRATORS) role. Then I applied an OIM authorization policy to the custom role to scale back the permissions for that role. However, the authorization policy does not seem to override the permissions granted by the inherited IDENTITY USER ADMINISTRATORS role. Is this the expected behavior?

Replication Steps on the question:
Create an Org say XYZ Org
Create an User - KKulk with XYZ Org as its Organisation
Create Role - XYZ Role, inheriting Identity User Admin Role
   - Leave the Role Category set to default and Owner to System Admin
Create Auth policy - XYZ Auth Policy
   * include XYZ Role in this Auth policy.
Assign the Role - XYZ Role to user - KKulk
Login as KKulk to OIM Admin Console.
You see the below behaviour:
  - permissions that are not included in XYZ Auth Policy like disable user, unlock user, delete user are displayed.


Sign In with your My Oracle Support account

Don't have a My Oracle Support account? Click to get started

My Oracle Support provides customers with access to over a
Million Knowledge Articles and hundreds of Community platforms