A centralized enterprise security and provisioning policy framework is
described. Enterprise wide security and provisioning is stored in a
hierarchical fashion in a centralized LDAP based Directory server. Each
policy and user maps directly to a unique entry in the directory. Policy
entries can be created at specific administrative points in the Directory
Information Tree instead of having to duplicate these policies as
attributes of every user entry in the directory. The policies can be
classified into provisioning, authentication, and authorization policies.