Previous Topic: Allow Nested Groups in Policies

Next Topic: AND Users/Groups Check Box

Specify AND/OR Relationships between Users/Groups

The AND Users/Groups check box lets you restrict authorization to users who are members of more than one user group or to a particular user who is a member of one or more user groups. When adding individual users and user groups in a user directory to a policy, you can specify AND relationships between them by selecting the check box. Alternately, you can specify OR relationships by clearing the check box.

When you specify AND relationships and apply the resulting policy to a user, the user must meet the following requirements to be authorized:

Important! Do not add two or more individual users to a policy and specify AND relationships. Because no single user can be more than one individual, the policy always fails.

To specify AND relationships between a user and one or more user groups or between multiple user groups in one user directory

  1. If the policy contains more than one user directory, select the tab corresponding to the user directory that you want on the Policy Properties pane.
  2. Select the AND Users/Groups check box on the user directory's tab.
  3. Click Apply.

    The icons next to the individual users and user groups in the selected user directory are updated to show AND relationships.

    Note: When you clear the check box and click Apply, the icons are updated to show OR relationships between the individual users and user groups in the selected user directory.