A policy server program evaluates one or more policy statements based on the
group
or groups to which a user belongs as well as other conditions. Each policy statement
expresses an implementation of the access policy of the network, and is associated
with a profile. The profile contains one or more actions that are to be applied
to the user. The policy server program determines the identity of the group or
groups to which the user belongs by referencing one or more group attributes contained
in a user object which is located in a directory on the network. The user object
and its group parameters are established when the user is added to the directory,
while a policy statement for a group can be created at any time.