All Products
Search
Document Center

CloudSSO:Manage system and inline policies

Last Updated:Jun 02, 2026

Add or remove system policies and create, modify, or delete inline policies for an access configuration.

Limits

  • Each access configuration supports up to 20 system policies and 1 inline policy. To increase these quotas, submit a request in Quota Center.

  • An inline policy document can contain up to 6,144 characters.

Add or remove a system policy

  1. Log on to the CloudSSO console.

  2. In the left-side navigation pane, click Access Configuration.

  3. On the Access Configuration page, click the name of the target access configuration.

  4. On the Policy tab, add or remove system policies.

    • Add a system policy

      1. Click Add System Policy.

      2. In the Add System Policy panel, select the policies to add and click Add.

      3. Click Close.

    • Remove a system policy

      1. Find the target system policy and click Remove in the Actions column.

      2. In the Remove System Policy dialog box, click OK.

If the access configuration is already provisioned for accounts in your resource directory, re-provision it for changes to take effect. Re-provision a permission set.

Create, modify, or delete an inline policy

  1. Log on to the CloudSSO console.

  2. In the left-side navigation pane, click Access Configuration.

  3. On the Access Configuration page, click the name of the target access configuration.

  4. On the Policy tab, manage the inline policy.

    • Create an inline policy

      1. Click Add Inline Policy.

      2. Enter a policy name and click OK.

      3. Edit the policy content and click Update Inline Policy.

        Inline policies use RAM policy syntax. Policy structure and syntax.

    • Modify an inline policy

      Edit the policy content and click Update Inline Policy.

    • Delete an inline policy

      1. Click Delete Inline Policy.

      2. In the Delete Inline Policy dialog box, click OK.

If the access configuration is already provisioned for accounts in your resource directory, re-provision it for changes to take effect. Re-provision a permission set.