You create access policies and add users to policies to give them appropriate roles and access.
- The system creates a default admin policy for you. You can add users to the default admin policy. This is the only admin policy available for tokenization vaults.
- You create additional policies for users and add the required users to each policy.
To create an access policy
Log in to the Cryptographic Security Platform Vault for Cryptographic APIs webGUI.
From the Home tab, select Security > Access Policies.
On the Manage Access Policies page, click the Create icon.
On the About tab of the Create Access Policy dialog box, complete the following:
Field
Description
Name
Enter the policy name.
Description
Optionally enter a description for the policy.
Role
Set this to User for all policies other than the admin policy.
Client Certificate for mTLS
To use mTLS with this policy, select the client certificate. Otherwise, leave this blank.
Users
Select the required users to be added to the policy.
If the vault is configured for Active Directory authentication, select User or Group and search for the required AD user or AD group.
Click Continue.
On the Permissions tab of the Create Access Policy dialog box, select whether to grant All Permissions or Specific Permissions to the users.
If you selected Specific Permissions, check the checkboxes for each permission that you want to assign.
Click Apply.