Managing policies
This system offers two methods for granting resource access: manual approvals through a self-service portal and automated assignments based on policies.
Policies automatically grant permissions to users or groups based on predefined criteria. They’re ideal for managing time-based access for projects with fixed durations.
Creating an access policy for targets
To create a policy that grants access to a specific target, such as a server or database:
-
In the PingOne Privilege admin console, click Targets.
-
Locate the target you want to grant access to and click More Info.
-
On the target details page, click Create Policy.
-
Click Continue.
-
Select the users or groups who’ll be granted access through this policy. Click Continue.
-
Enter a Policy Name and define the policy’s active period by setting a Start Date, Start Time, End Date, and Hours.
-
Click Submit to save and activate the policy.
Creating an access policy for cloud resources
To create an access policy for a cloud resource:
-
In the PingOne Privilege admin console, go to Access Management > Resources.
Creating an access policy for workloads
A workload policy defines the specific access rights for a workload identity. Each policy specifies the cloud resources a workload can access, the IAM roles granted, and the time during which the permissions will be valid.
Follow these steps to create a policy that grants a workload access to resources within a specific cloud account.
-
In the PingOne Privilege admin console, go to Workloads and click the name of the workload identity for which you want to create a policy.
-
In the Workload Information view, find the target cloud account and click + to open the Resource Catalog for that account.
|
If a workload is associated with multiple cloud accounts, you must create a separate policy for each account. |
Extending an access policy
To extend an active policy:
-
In the PingOne Privilege admin console, go to Policies.
-
Locate the policy you want to extend and click More Info to open the policy details page.
-
Click on Edit > Extend Expiry.
-
In the Extend Policy Expiry modal, update the End Time and click Save.
The policy is updated.