Previous Topic: Create a Legacy Administrator

Next Topic: Recreate a Deleted UI Administrator

Legacy Administrator Privileges

Administrator privileges are determined by the tasks that you enable for the administrator. These privileges allow administrators to use a set of Policy Server features.

The following tables describe the privileges associated with each combination of administrator task.

System Administrator Tasks

Tasks

Administrative Privilege

Manage System and Domain Objects

  • Create/edit/delete Agents, Agent Configuration Objects, Agent groups, Agent types, Host Configuration Objects, user directories, policy domains, authentication schemes, directory mappings, certificate mappings, registration schemes, and SQL query schemes.
  • All privileges for Manage Domain Objects.
  • Create/delete parent realms in all domains.
  • Create/edit/delete administrators.
  • Flush all caches, including cached resources.
  • Change global settings.
  • Delete Trusted Hosts

    Note: You cannot create or edit Trusted Host objects with this privilege, only delete them. To register Trusted Hosts, you must have Register Trusted Host privilege.

Manage Users

 

 

  • Flush all user session caches, or flush the user session cache of any individual user cache from any directory.
  • Enable/disable users in any directory.
  • Force password change on any user in any directory.

Manage Keys and Password Policies

  • Create/edit/delete password policies.
  • Manage keys.

Register Trusted Hosts

  • Register Trusted Hosts

    Domain Administrator Tasks

Tasks

Administrative Privilege

Manage Domain Objects

  • In managed domains: create/edit/delete rules, rule groups, responses, response groups, policies.
  • Edit top-level realms in managed domains (not resource filters).
  • Create/edit/delete nested realms in managed domains.
  • Flush specific realms from the resource cache, and flush all resources (in privileged domains) from the cache.

Manage Users

  • Flush user session caches for individual users in directories attached to managed domains.
  • Enable/disable users in directories attached to managed domains.
  • Force password change on users in directories attached to managed domains.

Manage Password Policies

  • Create/edit/delete password policies for users in directories attached to managed domains.


Copyright © 2009 CA. All rights reserved. Email CA about this topic