Apply hierarchical policy sets

You can apply multiple policy sets to the same role. For example, you might create a global policy set to define basic policies for all users and then create more policy sets for a subset of those users.

CyberArk Identity reads the policy sets from bottom to top on the Policy page when it installs the policies in a device. If the same policy has different settings in different policy sets, the setting in the last policy set—the top-most—is applied. If you want one policy setting to be enforced over another one, drag that policy set up in the list.

You can view the policy summary to see the policy set priority for each setting for the selected user. Go to Identity Administration portal > Core Services > Users , select a user, and click Policy Summary.