EIM mapping policy support and enablement

 

This information explains how to enable and disable policy associations for a domain.

Enterprise Identity Mapping (EIM) mapping policy support allows you to use policy associations as well as specific identifier associations in an EIM domain. You can use policy associations instead of, or in combination with, identifier associations.

EIM mapping policy support provides a means of enabling and disabling the use of policy associations for the entire domain, as well as for each specific target user registry. EIM also allows you to set whether a specific registry can participate in mapping lookup operations in general. Consequently, you can use mapping policy support to more precisely control how mapping lookup operations return results.

The default setting for an EIM domain is that mapping lookups that use policy associations are disabled for the domain. When the use of policy associations is disabled for the domain, all mapping lookup operations for the domain return results only by using specific, identifier associations between user identities and EIM identifiers.

The default settings for each individual registry are that mapping lookup participation is enabled and the use of policy associations is disabled. When you enable the use of policy associations for an individual target registry, also ensure that this setting is enabled for the domain. You can configure mapping lookup participation and the use of policy associations for each registry in one of three ways:

 

Parent topic:

Enterprise Identity Mapping concepts

 

Related concepts


Lookup information
Default domain policy associations
Default registry policy associations

 

Related tasks


Enabling policy associations for a domain
Enabling mapping lookup support and the use of policy associations for a target registry