HP BladeSystem bc2800 Administrator's Guide HP Session Allocation Manager (HP - Page 76

Create or Update a Policy, View Effective Policy, No Overrides Allowed, Create, Show Properties

Page 76 highlights

Table 4-1 Effective Hierarchical Policy Example (continued) Parameter Global Role OU SG1 SG2 User Effective 3P6 ON OFF ON OFF ON Not Assigned OFF 1 The order of policy assignment is User (highest) > Security Group > OU > Role > Global Policy (lowest). Individual parameters assigned at the User level override parameters set at the Group level, and so forth. Note that Parameter P2 is set at ON at the Global level, but is overridden by the OFF setting at the higher Role level, leaving an effective setting of OFF. 2 No Overrides Allowed can be set at any level to prevent override by parameters set at higher levels. Note that the No Overrides Allowed setting ON for Parameter P4 at the lowest Global level overrides the OFF setting at the higher Role level. This option does not affect whether or not the effective setting is forced upon the user. The effective setting is always forced. 3 At the Security Group level, HP SAM checks all Security Groups in alphanumeric order and uses the policy, if any, in the first Security Group encountered. Note that Security Group 1 is the first Security Group encountered, so the OFF setting for Security Group 1 leaves Parameter P6 with an effective setting of OFF, and the ON setting for Security Group 2 is ignored. The No Overrides Allowed option is set for a specific setting to prevent inheritance of other policies that would override the setting. Create or Update a Policy To create a new policy, click the Create button and type a new policy name. To update or edit an existing policy, click the policy name hyperlink. When the Update Policy window displays, set the value that you want or leave the value blank to allow it to inherit a value. When you update or create policies, you can view all available properties, or you can specify valid properties for either RGS or RDP. In the Show Properties list, select either ALL, RDP5, RDP6, or RGS to determine which values are active on-screen. NOTE: For more information about RGS, refer to your Remote Graphics Software documentation. View Effective Policy Use this feature to view the effective policy for a given user. See Table 4-1 Effective Hierarchical Policy Example on page 67. 1. Click View Effective Policy. 2. Type the UPN name of the user. 3. Click Go. The hierarchical merge of policies applied to the user is displayed. NOTE: You may also select a Role for the user to view the effective policy based on that Role, since the effective policy can be different with each Role to which that user belongs. 68 Chapter 4 Administration ENWW

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104

Parameter
Global
Role
OU
SG1
SG2
User
Effective
3
P6
ON
OFF
ON
OFF
ON
Not Assigned
OFF
1
The order of policy assignment is
User (highest) > Security Group > OU > Role > Global Policy (lowest)
. Individual
parameters assigned at the User level override parameters set at the Group level, and so forth. Note that Parameter P2 is set
at ON at the Global level, but is overridden by the OFF setting at the higher Role level, leaving an effective setting of OFF.
2
No Overrides Allowed
can be set at any level to prevent override by parameters set at higher levels. Note that the No
Overrides Allowed setting ON for Parameter P4 at the lowest Global level overrides the OFF setting at the higher Role level.
This option does not affect whether or not the effective setting is forced upon the user. The effective setting is always forced.
3
At the Security Group level, HP SAM checks all Security Groups in alphanumeric order and uses the policy, if any, in the first
Security Group encountered. Note that Security Group 1 is the first Security Group encountered, so the OFF setting for Security
Group 1 leaves Parameter P6 with an effective setting of OFF, and the ON setting for Security Group 2 is ignored.
The
No Overrides Allowed
option is set for a specific setting to prevent inheritance of other policies
that would override the setting.
Create or Update a Policy
To create a new policy, click the
Create
button and type a new policy name. To update or edit an existing
policy, click the policy name hyperlink. When the Update Policy window displays, set the value that you
want or leave the value blank to allow it to inherit a value.
When you update or create policies, you can view all available properties, or you can specify valid
properties for either RGS or RDP. In the
Show Properties
list, select either
ALL
,
RDP5
,
RDP6
, or
RGS
to determine which values are active on-screen.
NOTE:
For more information about RGS, refer to your Remote Graphics Software documentation.
View Effective Policy
Use this feature to view the effective policy for a given user. See
Table
4
-
1
Effective Hierarchical Policy
Example
on page
67
.
1.
Click
View Effective Policy
.
2.
Type the UPN name of the user.
3.
Click
Go
.
The hierarchical merge of policies applied to the user is displayed.
NOTE:
You may also select a Role for the user to view the effective policy based on that Role, since
the effective policy can be different with each Role to which that user belongs.
Table 4-1
Effective Hierarchical Policy Example (continued)
68
Chapter 4
Administration
ENWW