Use this pane to enable or disable and schedule group membership reconciliation for the domain. This process ensures that the domain local groups used to grant native AS/400 permissions, such as read or write access for the group member attribute, are created in EmpowerID and granted the proper native permissions.
Among the available Resource Enforcement Types are the following:
- No Action - No rights enforcement action occurs.
- Projection with No Enforcement - Changes to rights within EmpowerID occur only within EmpowerID; they are not passed on to the native environment.
- Projection with Enforcement - Changes to rights within EmpowerID occur within EmpowerID and are enforced within the native environment.
- Projection with Strict Enforcement - EmpowerID overrides any changes made in the native environment. All changes made must occur within EmpowerID to be accepted. Strict Enforcement only applies to Groups.
To set Rights Enforcement for Resource Role Groups, do the following:
- Click the Resource Enforcement Type edit icon to the right of the Resource Enforcement Type line.
- In the Change Resource Enforcement Type window that appears, select the resource enforcement type from the drop-down list, and then click OK to close the window.
- Click the Membership Schedule button to the right of the Membership Schedule line, enter the desired schedule in to the Set Schedule Interval window that appears and then click OK to close the window.
- Click the Enable this Functionality button so that the green check is visible.
Clicking the Run Now button immediately runs the Resource Role Group Membership Reconciliation process and adjusts the next run time to the Enforcement Schedule setting. You should not run the process until you have completed all configuration steps. |