Hierarchy Support for RSPD Configuration

The Role-Specific Policy Derivation (RSPD) configuration includes roles, policies, policy groups, and aliases. You can create roles, policies, and aliases and assign scopes to them based on the defined hierarchy.

Limitations to Hierarchical Support for RSPD Configuration

  • Policies can only be created as shared configuration and can only be mapped to global and site scopes.

  • Policy groups can only be created as shared configuration and can only be mapped to global scope.

  • Roles and aliases can be mapped to global, site-collection, site, and device scope. These cannot be mapped to the device collection scope.

  • Roles that are used in a policy does not follow reference rules. You can create a role at the child scope and use it in a policy that is at a parent scope.

  • You can override roles and aliases at any scope except the device collection scope.