Grant Rights to Modify Specific Properties of AD Objects
Using Security Roles you can allow users to modify specific properties of Active Directory objects. For example, you can enable users to modify only the Employee ID property of user accounts in Active Directory.
This tutorial includes step-by-step instructions on how to create a Security Role that will grant a permission to modify a single property of AD objects, and how to assign this role to users and groups.
-
Select the type of AD objects, a property of which you want to allow modifying.
Properties of the selected object type will be displayed in the Property-specific permissions section.
If the property you want to allow modifying is available for all types of objects (e.g. Description), you can apply the permission to all object types. For this purpose, select All object types above the list of object types.
-
Type the name or a part of the name of the desired property in the
filter edit box located in the Property-specific permissions section.
For example, if you want to allow modifying the Account Expires property, type 'expires'.
If the property you need is not available in the Property-specific permissions section, enable the Show all properties option.
-
Check the Allow option for the property.
- Click OK and then click Next.
You can select the following items:
-
All Objects - select if you want to allow the users or groups specified at
the previous step to apply the specified permission to any user account in any AD domain managed
by the Adaxes service.
-
Specific Domain - select a specific AD domain if you want to allow applying
the specified permission to any user in the AD domain you specify. If you select a domain, you
will need to specify the assignment scope in the Assignment Options dialog.
Assignment Options
Select All objects in this Domain. It means that users or groups specified at the previous step will be able to apply permissions of the new Role to all accounts in the selected domain. Click OK.
-
OU or Container - select a specific organizational unit or container if you
want to allow modifying account options of any user located in the selected OU or
container. If you select an OU or container, you will need to specify the assignment
scope in the Assignment Options dialog.
Assignment Options
To allow modifying account options of all children of the selected OU at any nesting level, click Child objects of this Organizational-Unit. To allow modifying account options of the direct child objects of the selected OU only, check also Immediate child objects only. Select the option you need and click OK.
-
Group - select a specific group if you want to allow applying the specified permission
to any user that is a member of the selected group. If you select a group, you will
need to specify the assignment scope in the Assignment Options dialog.
Assignment Options
To allow applying the specified permission to any group member, select Members of this Group. To allow applying the specified permission to direct group members only, check also Direct members only. Click OK.
-
Business Unit - select a Business Unit if you want to allow applying the specified
permission to user accounts that are members of a specific Business Unit. To view available
Business Units, select the Business Units item in the Look in drop-down
list.
If you select a Business Unit, you will need to specify the assignment scope in the Assignment Options dialog.
Assignment Options
In this case, the only applicable option is Members of this Business Unit. It means that the new Role permissions will be applied to all user accounts that are the members of the selected Business Unit. Select this option and click OK.
Select the object you need and click Add. When finished, click OK.
