Configure Authorization Profiles

An Authorization profile allows adding attribute-based parameters to the authentication process in order to control user access based on the appropriate attributes transmitted to the network remote access point (VPN, firewall, router etc.).

It is a list of parameters (sets of attributes or attribute/value pairs) that determines user authentication policies. Authorization profiles apply to both generic and RADIUS channels.

ActivID AS checks Authorization profiles as users request access, and then it either checks data or sends data back to the Access Controller.

When a user attempts a connection, an Authorization Profile Selection Rule defined in the channel configuration specifies what data to check or send back to the Access Controller.

An Authorization Profile Selection Rule is selected based on the role and Authentication Policy to be used for the user (dynamic authentication) and the roles granted to the user.

Each rule specifies the following conditions to control access:

Note: For push-based authentication via RADIUS, Check Before profiles are not supported (that is, Check Before attributes will not be applied).

You can create the Check Before and Send After profiles for an Authorization Profile Selection Rule when configuring a channel or independently as described in the following topics.

Topics in this section: