Reference Guide
...
Administration by Tenant Admin...
Policy Management
the kron pam role based management (user/device/policy) concept is based on realms individual creations are collected under a group and groups are connected to each other realms connect the groups together so that users can connect to devices by using policies the diagram below illustrates kron pam 's realm structure, which allows admins to manage specific users to authenticate on specific devices and authorize specific policies policies are applied to ssh/telnet connections rdp and sftp connections do not require policies please refer to section docid\ ijksjhfziw4il4g39qndt for policy definitions, policy tracking, and approval mechanism configurations