Policies

A policy defines rules that specify access privileges to a realm’s protected resources. Businesses posses resources, applications and services that they need to protect, manage and monitor. Policies control the access permissions and usage of these resources by defining when and how a user can perform an action on a given resource. A policy, when applied to an object, defines the resources that a particular object can access.

A single policy can define either binary or non-binary decisions. A binary decision is yes/no, true/false or allow/ deny. A non-binary decision represents the value of an attribute. For example, a mail service might include a mailboxQuota attribute with a maximum storage value set for each user. In general, a policy is configured to define what an object can do to which resource and under what conditions.

There are two types of policies that can be configured using OpenSSO; Normal Policies or Referral Policies. A normal policy consists of rules, subjects, conditions, and response providers. A referral policy consists of rules and referrals to organizations.