
19-22
XMS Configuration Guide
User Rights Management
Configuring the Policy Store in an XML file
Before using the Authorization Manager, system administrators must create and configure
a Policy Store repository. The Policy Store contains the AzMan-related configuration and
Vertigo Suite access restrictions. It is manipulated via a Microsoft Management Console
snap-in. Through the snap-in’s user interface, access to various components of the Vertigo
Suite can be restricted.
Prior to configuring the Policy Store, the type and location of the repository must be
determined. The repository can be housed in two types of containers; an
XML
FILE
or a
node in an
A
CTIVE
D
IRECTORY
installation of Windows 2003 functional level domain (see
page 19-8
).
The preferred repository is an Active Directory node, as it is best for multi-user
environments. Nevertheless, you should choose the
XML
FILE
type in situations where:
•
your Microsoft network domain is not Windows 2003
•
your domain administrator refuses to grant an external process access to an active
directory node
•
you have a computer with a network share that all other computers can read/write to
•
you have a good understanding of Microsoft Windows networking permissions
•
your network has a simple topology
Figure 19-24. User rights management configuration with Policy Store in an XML file
N
O T E
Configuring the Policy Store in an XML file should only be attempted by system
administrators and IT personnel whose responsibilities grant them jurisdiction over system
and network security. These professionals must also possess a solid understanding and
experience of Windows networking, including Windows Servers 2003, Active Directory,
Windows users management, as well as the Microsoft Authorization Manager.