19.4 Evaluating Password Policies

In Oracle Identity Manager, password policies are evaluated in the following scenarios:

The following is the order in which a user's effective password policy is evaluated:

  1. The password policy (if available) set for the user's home organization is applicable for the user.

  2. If no password policy is set for the user's home organization, then the policy of the organization at the next level in the organization hierarchy of the user's home organization is picked. This procedure of identifying an organization at the next level in the hierarchy of the user's home organization continues until an organization associated with a password policy is determined. This password policy is applicable to the user.

  3. If none of the organizations in the hierarchy has password policies set, then the password policy attached to the Top organization is applicable. If no password policy is attached to the Top organization, then the default password policy of the XellerateUsers resource is applicable.