Provision roles automatically
Use role provisioning rules to automatically add an Account Manager and grant access to the management UI based on attributes such as Active Directory group membership. Conversely, an Account Manager can be automatically removed if the rule that promoted the user to account manager evaluates false.
-
On the SAS console, select Policy > Automation Policies > Role Provisioning Rules.
-
To add a rule, click New Rule.
-
Configure the rule:
-
Rule Name—This must be a unique name that identifies the rule.
-
Auto Revoke—If selected, the Account Manager that is created by this rule is automatically removed if the conditions (such as group membership) are no longer valid.
-
Containers—This is container where the user must reside for the rule to evaluate true.
-
Role - This is the role that is assigned to the Account Manager. The list includes all configured roles.
-
Scope - The Account Management Groups list all configured groups. The Account Manager can access the groups that are included in the Applied by rule list. Use the arrow keys to move the groups between the two lists.
-
Groups Filter - The Virtual Server Groups list includes filtered groups in the Virtual Server.
-
Groups - The Virtual Server Groups list shows all groups defined for the Virtual Server. To apply a search filter to this list, use the Group Filter function to apply specific search criteria.Users that are members of one or more of the groups in the Used by rule list will be promoted to Account Manager. Use the arrow keys to move groups between the two windows.
-