Group and OU-based Self-Service Policy Configuration

Group and OU-based Self-Service Policy Configuration

What are self-service policies?

The self-service policies in ADSelfService Plus govern what self-service features users can avail. These policies have advanced settings which can be configured to apply restrictions on how users use the self-service features.

Group and OU-based Configuration

It is highly likely that not all users in a domain would require similar self-service permissions and restrictions. Keeping it in mind, ADSelfService Plus has an option to configure OU and group-based self-service policies. You can apply self-service policies to a domain or a group or even an OU.
Group and OU-based Configuration
Additionally, you can assign self-service policies to users based on their attributes as well.

Steps to assign self-service policies based on user attributes:

  1. Navigate to Configuration > Self-Service > Policy Configuration.
  2. Select the advanced button of the respective policy, and navigate to the General tab.
  3. Click more and select the Add Filter option.
  4. Choose an attribute, select the condition (Example: Contains, Starts With, etc.), and enter the value against which the condition has to be checked. (Example: Department Contains Marketing).
  5. Click the + button to add more conditions if required.
  6. Click OK to save the settings.
group-and-ou-based-self-service-policy-configuration

Prioritize Self-Service Policies

You can prioritize self-service policies so that if a group or an OU falls under multiple self-service policies, the self-service policy with the highest priority will take effect.
Prioritize Self-Service Policies

We will see more about the settings available in the Advanced Policy Configuration next week.



                  New to ADSelfService Plus?

                    • Related Articles

                    • How to clone existing policies in ADSelfService Plus?

                      Solution: ADSelfService Plus allows you to configure multiple self-service policies based on users' domains, OUs, and group memberships, and lets you decide which sets of users will have access to what self-service features. You can even clone an ...
                    • Password Policy Enforcer configuration

                      ADSelfService Plus' Password Policy Enforcer enables admins to utilize advanced password policy controls like banning weak passwords and keyboard sequences for users' on-premises AD accounts and cloud accounts, including Microsoft 365 and Google ...
                    • How to resolve the "Permission Denied" error in ADSelfService Plus

                      To resolve the Permission Denied error in ADSelfService Plus, you need to ensure that the respective users are part of the selected OUs or Groups in the policy configuration. To do this, please follow the steps below: Log in to ADSelfService Plus as ...
                    • How to enable offline MFA in ADSelfService Plus

                      ManageEngine ADSelfService Plus supports offline multi-factor authentication (MFA) for Windows machine logins, User Account Control (UAC) prompt elevation, and Remote Desktop Protocol (RDP) server authentication when the product server is ...
                    • Configuring QR code-based authentication for Active Directory-based actions

                      QR code-based authentication is a type of multi-factor authentication method that involves scanning a QR code with an app in order to verify one's identity. When authenticating into a service using MFA, users need to provide their account credentials ...