Role-Specific Policy Derivation (RSPD) Configuration
Can I create Roles and Aliases as local configuration objects?
Yes, Roles and Aliases can be created as local configuration objects at any scope except at Device Collection scope.
What is meant by "Roles do not follow reference rules used in policy"?
This statement implies that roles can be at any child scope for example, a specific role can be at a Site scope and a policy can be at the Global scope.
Can I create a policy with local configuration role or local configuration alias?
A policy can refer local configuration role but not local configuration alias.
What happens if roles or aliases are mapped to Device Collection scope?
The scope mapping fails, and an error message is displayed.
What happens when policy-group is mapped to other scopes other than the Global scope?
The scope mapping fails, and an error message is displayed.
What happens when a policy is mapped to other scopes other than Global and Site scope?
The scope mapping fails, and an error message is displayed.
What is the order of scope mapping for RSPD configurations through API?
You must map the policy group first. There is no definite order for roles and policy mapping. Aliases get automatically mapped when policy is mapped if, they are not mapped previously. Devices receive configuration only after mapping the roles and policies.