To create a default domain policy association, you must be connected to the Enterprise Identity Mapping (EIM) domain in which you want to work and you must have EIM access control at one of these levels:
Because you can use policy associations in a variety of overlapping ways, you need to have a thorough understanding of EIM mapping policy support before you create and use policy associations. Also, to prevent potential problems with associations and how they map identities, you need to develop an overall identity mapping plan for your enterprise before you begin defining associations.
In a default domain policy association, all users in the domain are the source of the policy association and are mapped to a single target registry and target user. You can define a default domain policy association for each registry in the domain. If two or more domain policy associations refer to the same target registry, you can define unique lookup information for each of these policy associations to ensure that mapping lookup operations can distinguish between them. Otherwise, mapping lookup operations may return multiple target user identities. As a result of these ambiguous results, applications that rely on EIM may not be able to determine the exact target identity to use.
To create a default domain policy association, complete these steps: