keycloak-scim/authorization_services/topics/policy-group-policy-extend-children.adoc
Stian Thorgersen de7a1403ce Convert Authorization Service to a flat topic structure (#212)
* Convert Authorization Service to a flat topic structure

* Fix issue with toc being cut
2017-10-09 08:38:46 +02:00

12 lines
No EOL
681 B
Text

[[_policy_group_extend_access_children]]
= Extending Access to Child Groups
By default, when you add a group to this policy, access restrictions will only apply to members of the selected group.
Under some circumstances, it might be necessary to allow access not only to the group itself but to any child group in the hierarchy. For any group
added you can mark a checkbox *Extend to Children* in order to extend access to child groups.
.Extending Access to Child Groups
image:{project_images}/policy/create-group-extend-children.png[alt="Extending Access to Child Groups"]
In the example above, the policy is granting access for any user member of *IT* or any of its children.