In addition to using access roles to grant access to applications, you can also use access roles to prevent members of access roles from accessing an application. To prevent access role members from accessing an application, you exclude the roles from CA SiteMinder® policies. When a user who has been assigned the excluded access role in CA Identity Manager tries to access a protected resource, the Policy Server verifies exclusion of the CA Identity Manager role to the assigned user. Upon verification, it blocks access to the resource.
Follow these steps:
The Users tab contains tabs for each user directory and CA Identity Manager Environment included in the policy domain.
The CA SiteMinder® Policy CA Identity Manager Role dialog opens.
The opposite procedure removes roles from the Current Members list.
A red circle with a slash appears to the left of the excluded roles.
|
Copyright © 2014 CA.
All rights reserved.
|
|