Documentation
Home
Products
DirX Access DirX Audit DirX Directory DirX Identity
Get Support

DirX Access

    • Copyright
    • System Overview
    • Glossary
      • Industry Terms Glossary and Abbreviations
      • DirX Access Terms Glossary and Abbreviations
    • Installation And Deployment
      • Pre Installation
        • Planning Your Installation
        • Deploying Application Repository
      • Running the Installer
      • Initial Configuration
      • Direct Application of System Actions, Configuration and Shadow User Tree
      • Crypto Material Management
      • Sanity Check
      • PEP Deployment
      • User Repository-less Deployment
      • Migration
      • System Deployment
    • Cache Server
    • Bridge
      • Client TLS Authentication for Request Resolution
    • Server
      • Administration Guide
        • Administrative Tools
        • Administrative Tasks
          • Configuration
            • Authentication
              • Authentication Application
              • Authentication Methods
                • Authentication Application Authentication Methods
                • Basic Authentication Methods
                • Composite Authentication Methods
                • FIDO Authentication Methods
                • Form Authentication Methods
                • OAuth Authentication Methods
                • OAuth Client Authentication Methods
                • One-Time Password Callback Authentication Methods
                • HMAC-Based One-Time Password Authentication Methods
                • Time-Based One-Time Password Authentication Methods
                • Password Change Authentication Methods
                • SAML Authentication Methods
                • Selection Authentication Methods
                • Third-Party Token Authentication Methods
                • Trusted Authentication Methods
                • Windows Authentication Methods
                • X.509 Authentication Methods
              • FIDO Metadata Service
              • FIDO Metadata Statements
              • Kerberos SPN Table
              • Logout
                • SingleLogout
                • Single Logout Peers
                  • OAuth authorization server single logout peer
            • Authorization
              • XACML Attribute Category
              • XACML Attribute Construction Template
              • XACML Attribute Value Mapping
              • XACML Attribute Value Construction Template
              • XACML Policy Interpretation Template
              • XACML Request Construction Template
            • Extension Modules
              • Callout Handler
            • Federation Endpoint
              • OAuth FEP
                • OAuth Client Federation Endpoint
                • OAuth Client Metadata
                • OAuth Provider Federation Endpoint
                • OAuth Server
                • OAuth Server Metadata
              • SAML FEP
                • SAML Federation Endpoint Identity Provider
                • SAML Metadata
                • SAML Federation Endpoint Service Provider
              • WS-Federation
                • WS-Federation Endpoint
                • WS-Federation Metadata
            • Key management
              • Crypto Container
            • Data Services LDAP
            • Policy Decision Points
              • File-Based Policy Decision Point
              • Service-Based Policy Decision Point
            • Policy Enforcement Points
              • Cloud Foundry PEP
              • Deployable Web PEP
              • Other PEP
              • Plain Web PEP
            • Policies
              • ABAC Policy Container
              • Authentication Policies
                • Authentication Policy
                • Authentication Risk Conditions
                  • Callout Risk Condition Type
                  • IP Address Range Risk Condition Type
                  • Login Failures Risk Condition Type
                  • Login Interval Risk Condition Type
                  • Protocol Header Risk Condition Type
                  • Resource Sensitivity Risk Condition Type
                  • Time Range Risk Condition Type
                  • User Attribute Risk Condition Type
                  • User-Context-Aware Risk Condition Type
              • RBAC Authorization Policies
                • RBAC Authorization Actions
                • RBAC Authorization Policies
                • RBAC Authorization Rules
                • RBAC Authorization Conditions
                  • Assurance Level Condition Type
                  • Authentication Method Condition Type
                  • IP Range Condition Type
                  • Ownership Condition Type
                  • Resource Parent Condition Type
                  • Time Range Condition Type
                • RBAC Obligations
                  • Expression Obligation
                  • Injection Obligation
                  • Source Obligation
                • Roles
              • Resources
            • REST Services
              • Configuration REST service
              • Legacy REST service
              • SCIM REST Service
              • SSO REST Service
              • System Actions REST Service
            • Servers
              • Cluster
              • Server Port Assignments
              • Server
            • SOAP Services
              • Provisioning SOAP Web Service
            • Subject
              • External Subject Representation
                • OAuth Token
                  • OAuth Attribute Template Construction
                  • OAuth Attribute Value Template Construction
                • Request Injection
                  • Request Injection Template
                  • Request Injection Value Template
                • SAML Assertion-based External Subject Representations
                  • SAML Assertion Construction Template
                  • SAML Attribute Statement Construction Template
                  • SAML Attribute Construction Templates
                  • SAML Attribute Value Construction Template
                  • SAML Authentication Context Template
                  • SAML Authentication Statement Construction Template
                  • SAML Subject Construction Template
              • Internal Subject Representation
                • Persistent Data
                  • RBA Data Collector
                  • Subject Template
                • SAML Assertion-based Internal Subject Representations
                  • SAML Assertion Interpretation Template
            • User Repository
            • Web Applications
              • Custom Web Application
              • Single Page Web Applications
                • Single Page Application
                • Single Page Web Application Plugins
                  • Credentials Manager Plugin Application
                  • Manager Plugin Application
                  • Manager Relations View
          • System Actions
            • Export Configuration
            • Import Configuration
            • Deployment
              • BridgeDeploymentSysAction
              • Pep Deployment
                • ApachePepDeploymentSysAction
                • IisPepDeploymentSysAction
                • JettyHandlerPepDeploymentSysAction
                • ServletFilterPepDeploymentSysAction
                • TomcatPepDeploymentSysAction
              • ServicesDeploymentSysAction
              • Web App Deployment
                • SpaPluginWebAppDeploymentSysAction
                • WebApplicationDeploymentSysAction
            • Keystore Management
              • GenerateKeystoreSysAction
              • ImportKeystoreSysAction
          • Scenario Wizards
          • Visualization
            • Relations View
        • Functional Topics
          • Authentication
            • Single Logout
              • OAuth Single Logout
              • OAuth Single Logout
            • Authentication Application
              • Composite Authentication Method
              • Password Change
              • Authentication Based on Trusted Channel
            • Integrated Windows Authentication
            • FIDO Authentication Methods
            • Risk-based Authentication
            • Name Resolution
            • Enabling Authentication Methods
            • Sharing Credentials Across Multiple Authentication Methods
            • Anonymous Access
            • Just in Time Provisioning to Application Repository
          • Federation
            • SAML
              • SAML Keywords
              • SAML Proxying
              • SAML Signing and Encryption
            • WS-Federation and WS-Trust
            • OAuth
              • OAuth 2.0 Authorization Framework
              • Resource-Centric Authorization Service
              • Configuring SSL/TLS Client Truststore and HTTPS Proxy for OAuth Client FEP
          • Authorization
            • Role Enablement Authorities
            • DirX Access Authorization
          • User Data Management
            • User Data Management via SCIM 2.0 and the Application Repository Service
          • Auditing
        • Non-Functional Topics
          • Port Assignments
          • Cross-Origin Resource Sharing (CORS)
          • Session Management
          • System Monitoring
          • System Logging
          • Distributed Cache and Performance
          • Keystore Management
          • Password/Keys Obfuscation
          • Changing the Server Side JVM Restart Threshold
          • Resource Identification and URI Normalization
          • Servlet Filter Parameter Sanitization
          • LDAP
          • Custom System Properties
      • Integration Guide
        • Employing External Plug-in Modules
        • Web Services Communications
          • Federation SOAP Web Service
          • Provisioning SOAP Web Service
          • SSO REST Web Service
          • SysActions REST Web Service
          • Config REST Web Service
            • Configuration Export Config REST Web Service
            • Query Options Config REST Web Service
            • Fine-grained Patching of Resources
            • Configuration Object Metadata Config REST Web Service
          • SCIM 2.0 REST Web Service
            • Record Metadata SCIM 2.0 REST Web Service
            • Users and Groups SCIM 2.0 Endpoints
          • Legacy REST Web Services
            • Sessioning Legacy REST Web Services
            • User Credentials and Data Legacy REST Web Services
        • Audit Event Plug-ins
        • Credential Validation Plug-ins
        • Attribute Finder Plug-in for Authentication
        • Third Party Authentication Token Finder Plug-in
        • Name Mapping Plug-in
        • Attribute Finder Plug-ins for Authorization
        • CRL Finder Plug-ins
        • SSO Event Plug-ins
        • User Consent Plug-ins
        • Risk Condition Plug-ins
        • Authentication Application Success Plug-ins
        • OTP Callback Callout Plug-ins
        • Password Propagation Plug-ins
        • Voucher Propagation Plug-ins
        • RBA Data Plug-ins
        • Customizing DirX Access Components
        • Deploying Custom Web Application
    • Performance
      • OAuth Authorization Code Flow
      • SAML Assertion with Implicit Login
      • Perform SSO
      • PEPs
        • PEP for Apache HTTP Server
        • PEP for Internet Information Services
    • Template Files
      • Configuration Template Files
        • dxaConfigCluster.json
        • dxaConfigServer.json
        • dxaConfigPortAssignmentSSL.json
        • dxaConfigReaAdministration.json
        • dxaConfigUserRepository.json
        • dxaConfigSubjectTemplate.json
        • dxaConfigRbacAdministration.json
        • dxaConfigAuthNBasic.json
        • dxaConfigAuthNAuthNApp.json
        • dxaConfigRestForConfig.json
        • dxaConfigSPA.json
        • dxaConfigManager.json
        • dxaConfigRestForSCIM.json
        • dxaConfigCredentialsManager.json
      • SUT Template Files
        • dxaUserDirXAccessAdministrator.json
      • System Actions Template Files
        • dxaCryptoGenerateKeystoreSecCommClient.json
        • dxaCryptoGenerateKeystoreSecCommServer.json
        • dxaDeployWebAppConfigRest.json
        • dxaDeployWebAppSysActionsRest.json
        • dxaDeployWebAppSPACore.json
        • dxaDeployWebAppPluginManager.json
        • dxaDeployWebAppDxaAa.json
        • dxaDeployBridge
    • Peps
      • Cloud Foundry PEP
      • PEP Communication Resolution
      • Request Logging at Java PEPs
      • PEP for Apache HTTP Server
      • PEP for Internet Information Services
    • Datasheets
DirX Access 9.1
  • DirX
  • DirX Access
    • 9.1
  • DirX Audit
    • 9.1
    • 9.0
    • 7.2
  • DirX Directory
    • 9.1
  • DirX Directory Manager
    • 3.2.0
  • DirX Identity
    • 9.0.0
    • 8.10.15
    • 8.10.14
Home
  • DirX Access
  • Server
  • Administration Guide
  • Administrative Tasks
  • Configuration
  • Policies
  • RBAC Authorization Policies

RBAC Authorization Policies

RBAC Authorization Policies allow you to create, modify, duplicate, and delete authorization policies that apply authorization rules controlling access to actions on protected resources.

User-Context-Aware Risk Condition Type RBAC Authorization Actions

DirX is a registered trademark © Copyright ${currentyear}, Eviden SAS – All rights reserved.

The UI for this site is derived from the Antora default UI and is licensed under the MPL-2.0 license. Several icons used are provided by Google and are licensed under the Apache License Version 2.0.