Previous Topic: How CA Access Control Finds a User Record

Next Topic: Guidelines for Managing Accessors in Enterprise Stores

Integration with the Enterprise User Stores

Typically, you configure CA Access Control to use the groups and users that are defined in the enterprise user stores.

If you do configure CA Access Control like this, by default, when an access rule that references an enterprise user or group is created, or when a user logs in to the operating system, CA Access Control creates a record in its database for that user or group, if one did not exist before. These records have the class XUSER (for enterprise users) or XGROUP (for enterprise groups). They hold the properties that CA Access Control requires to enforce access rules. You do not need to manage them, because CA Access Control creates them as required.

The only properties of an enterprise user or group that CA Access Control fetches from the enterprise user stores are the names and the group membership properties.