Warning! Audit Deprecated
Information
Set the 'Check Roles and Policies' setting to [All Web applications and EJBs].
Without checking all web applications and EJBs, roles and policies will not be enforced for the entire domain, leaving a malicious user opportunity to gain unauthorized access.
Solution
To enable 'Check Roles and Policies' follow the steps specified below:
1. Login to the Administration Console.
2. In the Change Center, click Lock & Edit.
3. In the left pane, select the Domain name.
4. Select Security Realms > Name of the active Security Realm.
5. Select Configuration > General tab.
6. Select Advanced.
7. Set the 'Check Roles and Policies' to [All Web applications and EJBs], click Save.