Hello,
To be able to create and delete Password Self-Service Policies, a user needs to be granted the permission to create and delete objects of type PasswordSelfServicePolicy under the Password Self-Service Policies Container. To be able to modify Policies, the user needs to be granted the Full Control permission for objects of type PasswordSelfServicePolicy. Additionally, if you want to grant the user the permission to view Password Self-Service Statistics, you need to grant the user the View Password Self-Service Statistics permission for the PasswordSelfServiceStatistics object type. To create a Security Role that grants such permissions:
- Create a new Security Role.
- On the 2nd step of the Create Security Role wizard, click Add.
- In the dialog that appears, switch the radio button to Only selected object types.
- Select the Show all object types option.
- Select the PasswordSelfServicePolicyContainer object type.
- In the Operations on child objects section, select the Create Child Objects permission in the Allow column to allow creating new Password Self-Service Policies.
- To allow deleting Password Self-Service Policies, select the Delete Child Objects permission in the Allow column.
- Click the Select object types link.
- Select the Show all object types option.
- Select the PasswordSelfServicePolicy object type.
- Click OK two times.
- Click the Add button again.
- In the dialog that appears, switch the radio button to Only selected object types.
- Select the Show all object types option.
- Select the PasswordSelfServicePolicy object type.
- In the General permissions section, select the Full Control permission in the Allow column.
- Click OK.
- Click the Add button again.
- In the dialog that appears, switch the radio button to Only selected object types.
- Select the Show all object types option.
- Select the PasswordSelfServiceStatistics object type.
- In the General permissions section, select the View Password Self-Service Statistics permission in the Allow column.
- Click OK.
- On the 3rd step, assign the Security Role to the users who need this permission and include Configuration Objects in the Assignment Scope of the Role.