You are viewing an old version of this page. View the current version.

Compare with Current View Page History

« Previous Version 18 Next »

Access Control by time is the most common policy used by our customers.  It can be used in two ways.  1) To only grant an exclusive group of users to Applications.  2)Restrict access to applications by time/date.

Senario 1: Users in the 2fa_Access AD security group will have access to OWA, whereas users who are not will be denied access,





In the Administration Console, the policies can be accessed via either under Shortcuts>Check Policies


or


Administration>Policies 



In the Category dropdown, you will see four Access Control policies.  Select Access Control.


Click Search


  


A list of Access Control policies will appear underneath, If you have not yet created one then only the default system policy will display.

The default policy allows system-wide access to all applications at any time, buy all users.


Do Not Delete or Edit the default system policy.  Making any changes to this policy could result in you not being able to access the Administration Console even using the System Admin account. 


It is best practice to create two new policies.  One to allow access, One to deny access.


Click the Create button on the top right.



Create a new policy that will allow users belonging to a specific AD Group to access OWA

OptionValue
CategoryAccess Control
HolderGroup
DomainSelect your domain
GroupSpecify the AD group name (You may need to type in the initial characters before it appears in the dropdown list)
NameSpecify a name that describes the policy
Description(Optional)
EnabledCheck to enable the policy
ApplicationSpecify Application(s) or leave blank if the policy applies to all applications
AccessAllowed

Create a new policy that will deny access to users in the rest of the domain.

OptionValue
CategoryAccess Control
HolderDomain
DomainSelect your domain
NameSpecify a name that describes the policy
Description(Optional)
EnabledCheck to enable the policy
ApplicationSpecify Application(s) or leave blank if the policy applies to all applications
AccessDenied


  • No labels