Pattern-based policies
converged bridge access management supports attribute based policies, policies that apply to all resources and resource pattern based policies patter based policies can be assigned directly to users, access group and service ids, providing flexible control over resource access resource pattern based policies allow administrators to define a resource pattern (resource crn) and apply one policy across multiple resources that match the specified pattern administrators can also configure a policy for an individual resource when more granular control is required administrators can create, view, assign, update and validate resource pattern based policies through the assign access policy workflow during authorization, access evaluation includes the resource pattern based policies associated with the user or the access group to which the user belongs the okta fga authorization engine evaluates these policies to determine whether access is allowed for resources that match the configured pattern resource pattern definitions a resource pattern identifies the resources that a policy applies to when a wildcard ( ) is included in part of the pattern, all values are accepted in that position example resource pattern crn\ v1\ dx\ local\ iam\ global\ delivery\ public\ domain example individual resource identifier crn\ v1\ dx\ local\ insights\ global 5c306798dec5 1\ public\ dashboard 1aeb4e99 2c80 43f1 93bf b55c2953d346 pattern validation rules and allowed characters consider the following guidelines when creating pattern definitions to ensure values comply with the required validation rules and contain only supported characters only the following characters are allowed in the pattern uppercase letters ( a z ), lowercase letters ( a z ), numbers ( 0 9 ), colon ( ), asterisk ( ), underscore ( ), period ( ), forward slash ( / ), and hyphen ( ) spaces are not allowed in the pattern the colon ( ) acts as a separator between pattern segments when the wildcard character ( ) is specified between colons (for example, ), no other characters can appear between the colons the colon character ( ) is used only as a part separator and cannot be included as a value within any part of the pattern the wildcard character ( ) cannot be combined with any other character the api validates the pattern and rejects any value that contains characters outside the allowed character set the allowed character pattern is \[a za z0 9 / ] a part value may be empty (for example, ) assign a pattern based policy the steps for assigning a pattern based policy are the same for users, access groups, and service ids the only difference is the entry point used to access the entity follow the steps below to assign a resource based on patterns policy from the main menu , go to administration → access management → bridge access management from the left navigation menu, select users , access groups or service ids , depending on the entity learn more users to learn more about how to assign policies to a user, see users docid 7caos2ibikfbh9x bz51x access groups to learn more about how to assign policies to an access group, see access groups docid\ hzc4qy5gh7gwklhfysayc service ids to learn more about how to assign policies to a service id, see service ids docid\ i2wxfqp2tstqi7gfvof18 locate the user, access group or service id, you want to configure and click on +assign access policy workflow when assigning the policy, select resource based on patterns in the scope field enter the resource pattern definition the resource pattern must use the required colon separated format invalid patterns cannot be saved and an error message is displayed to verify the assignment, open the access policies tab and confirm that the policy is displayed with the resources based on patterns scope once the policy is assigned, access is granted according to the configured resource pattern and authorization is evaluated against the matching resources editing access group pattern based policies policies assigned to an access group can be edited when policy settings need to be updated changes to an access group policy can affect all users who inherit access through that access group from the main menu , go to administration → bridge access management → access groups on the access groups page, locate the access group whose policy you want to modify and select the access group name select the access policies tab locate the policy under the access policy name column and select the policy name select edit update the policy configuration as required and save your changes