My current view of Ranger Policy is that the policy works by name matching. So that, for example, if I don't sync user from LDAP or Kerberos (for the principal), I can just add the internal user (from Ranger UI) with the same name as in LDAP/Kerberos/UNIX, and apply the policy to that internal user to make it works for external user with the same name.
Is this a correct understanding of how Ranger Policy works?
Thanks,
Franky