This topic describes how to manage system and inline policies.
Limits
You can configure up to 20 system policies for each access configuration.
The document of an inline policy can be up to 6,144 characters in length.
Add or remove a system policy
Log on to the CloudSSO console.
In the left-side navigation pane, click Access Configuration Management.
On the Access Configuration Management page, find the desired access configuration and click its name.
On the page that appears, click the Details tab and then the System Policy tab.
Add or remove a system policy.
Add a system policy
Click Add.
In the Add System Policy panel, select the desired system policies and click Add.
Click Close.
Remove a system policy
On the System Policy tab, find the desired system policy and click Remove in the Actions column.
In the Remove System Policy message, click OK.
If you add a system policy to or remove a system policy from an access configuration that is provisioned for the accounts in your resource directory, you must re-provision the access configuration for the modification to take effect. For more information, see Re-provision an access configuration.
Create, modify, or delete an inline policy
Log on to the CloudSSO console.
In the left-side navigation pane, click Access Configuration Management.
On the Access Configuration Management page, find the desired access configuration and click its name.
On the page that appears, click the Details tab and then the Inline Policy tab.
Manage inline policies.
Create an inline policy
Click Create Inline Policy.
In the Create Inline Policy panel, edit the policy document and click OK.
For information about the policy syntax, see Policy structure and syntax.
Modify an inline policy
On the Inline Policy tab, click Edit.
In the Edit Inline Policy panel, modify the policy document and click OK.
For information about the policy syntax, see Policy structure and syntax.
Delete an inline policy
On the Inline Policy tab, click Delete.
In the Delete Inline Policy message, click OK.
If you create, modify, or delete an inline policy for an access configuration that is provisioned for the accounts in your resource directory, you must re-provision the access configuration for the modification to take effect. For more information, see Re-provision an access configuration.