Global policy enforcement
Global policy enforcement is the manner in which the IBM® Security Identity Manager system globally allows or disallows accounts that violate provisioning policies.
When a policy
enforcement
action is global, the policy enforcement
for any service is defined by the default configuration setting. You
can specify one of the following policy enforcement actions to occur
for an account that has a noncompliant attribute.
- Mark
- Sets a mark on an account that has a noncompliant attribute.
- Suspend
- Suspends an account that has a noncompliant attribute.
- Correct
- Replaces a noncompliant attribute on an account with the correct attribute.
- Alert
- Issues an alert for an account that has a noncompliant attribute.
Note: If a service has a specific policy enforcement
setting, that setting is applied to the noncompliant accounts; the
global enforcement setting does not apply to them.