When you click 'Specify Web Application user policy link', you will land on the Policy for Web Application page. This page will let you manage the Web Application User Policy.


Policy for Web Application page’s direct link - /_admin/policy.aspx

There are many ways to manage the permissions on the site collection; i.e., you add primary or secondary site collection administrator from central admin or add an extra site collection administrator within the site collection. This is easy for single site collections, but if you have to give the permissions to a user or a group of the users into all the site collections in a farm, then add the user manually in all the site collections or use the policy for the Web Application option from central admin.

There are many accounts which require the permission in the Web Application including:

You can also restrict the permission for single user or a group at the Web Application level. Once you deny the permission, then the user or the group will not get access to the server.

Policy of the Web Application is in a centralized location, where we can manage the permissions for the Web Application. There are a couple of different level of permissions, you can assign it to a single user or a group.

Zone- As we know, a Web Application can be in multiple zones (Default, intranet, internet, extranet and Custom).Thus, we can set the permissions at the single zone or all the zones. When you set a permission for the Web Application, you select the correct zone or select all the zones.

System Account- Sometimes you don’t want to show the account’s information to the end user to avoid any information leak or any information leak about the enterprise Service accounts. Thus, select this system account option, when you add a user into Policy for the Web Application, then account is displayed as SharePoint\System regardless of its name & details.

To Add a User in Policy of the Web Application

In order to add a user into the Web Application policy, please follow steps given below.

To edit permission for a User in the Policy of Web Application

To edit the permission for an existing user, please follow the steps given below.

To delete the permission for a user in the policy of the Web Application

To edit the permission for the existing user, please follow the steps given below.

Note

You have to be careful when granting the permission to a user or a group into the policy of the Web Application because this permission applies to all the site collections in the Web Applications.