Access Policy Configuration for Zero Trust Approach16 minutes to read
Post establishing the trust score parameters and weightage, you can create access policies to implement the policy-based access method in the organization, utilizing the generated user and resource trust scores. These access policies can be tailored to meet the specific needs and requirements of the organization, allowing users to be granted appropriate access privileges to the corresponding resources in a detailed and dynamic manner. Navigate to 'Admin >> Zero Trust >> Access Policy' to create the new access policies with desired conditions concerning your requirements. Every access policy created for this zero trust approach is to be approved by another administrator of the organization to check for valid access policy conditions towards the users and the resources. Note: The access policy created with multiple conditions for a resource does not apply to the owner of the resource except for the condition with Self-Service Privilege Elevation access. 1. Creating an Access PolicyTo create an access policy for implementing policy-based access privilege, do the steps that follow:
1.a Creating an Access Policy ConditionTo create a condition in an access policy, do the steps that follow:
1.b Defining Criteria and Criteria ExpressionNow you have to provide the criteria for this access policy condition that have to be met to get further allowed access privileges via this access policy condition:
1.c Allowed Access If the Criteria Expression is MetYou can enable the access privileges here based on the respective users' requirements to which the condition is to be applied. If the above-defined criteria expression is satisfied, the user associated with this condition is given access privileges that you enabled in this condition. Note: A minimum of one allowed access is required to save the access policy condition.
1.d Actions If the Criteria Expression is Not MetThe operation you select in this section will be performed when the user/resource fails to meet the above-defined criteria expression of a condition.
Applies To: This option allows you to include or exclude users from the condition based on your policy-based access privilege requirements. By associating users with the condition, you can enforce the respective access policy for the users via relevant user groups. To learn how to create an access policy that involves multiple conditional cases, you can refer to this real-time scenario help document. 2. Mindful While Creating Multiple Conditions in an Access Policy
Related Document | |