0 votes

We are using the SeeAlso attribute to store who is responsible for specific accounts.

We do not wish to use the Manager field, because the Manager/Direct Report structure is reflected in org charts in many applications we use.

So we implemented the SeeAlso attribute to store the DN of the "Account Owner"

The only bit we are missing is to grant permissions to edit a user when the initiatior DN is present in the SeeAlso attribute. This way, if my DN is present in the SeeAlso attribute for a user, I have rights to, for example, extende the expiration date of an account.

Is that possible?

by (310 points)

1 Answer

+1 vote
by (177k points)
selected by
Best answer

Hello Manuel,

Yes, it is possible using a dynamic Business Unit and a Security Role. For each user the Business Unit will contain only the accounts that have them specified in the See Also property and will be used to assign the Security Role. For information on how to create dynamic Business Units, have a look at the following tutorial: https://www.adaxes.com/tutorials_ActiveDirectoryManagement_CreateDynamicBusinessUnit.htm. On step 3 of the guide, select Query Results and enter the following LDAP filter into the corresponding field: (&(sAMAccountType=805306368)(seeAlso=%distinguishedName%)) image.png The Security Role will look like the following: image.png Additionally, you might consider using the Assistant or Secretary property to store managers. In this case, you will not need a Business Unit and the Security Role will look like the following: image.png

0

Thank you very much, this solves it.

We wish to use the SeeAlso because it allows multiple values to be used (so that multiple users can have permissions over multiple objects).

This worked perfect as you suggested

+1

Hello Manuel,

Thank you for the confirmation.

For you information, the Secretary property is also multi-valued, so you might consider using it to store multiple managers and avoid using the Business Unit.

0

I wasn't aware Secretary is also multi-valude. Great info, thanks!

0

After giving it some thoughts, using the Secretary field makes sense, considering that is also multi valued.

I am a little confused by the example you show, where the permissions show the Trustee to be "Assistant". Shouldn't it be "Secretary"?

image.png

+1

Hello Manuel,

Yes, you are absolutely right. It was just an example on how you can use either of the security principals. According to your screenshot, the Security Role should work just fine.

Related questions

0 votes
1 answer

I'd like to be able to either send an email report or export a CSV of all of the business rules carried out when a user is disabled. This would be ... Management Activity section but this includes things that weren't part of the disable operation. Thanks

asked Feb 19 by bavery (250 points)
0 votes
1 answer

Dear Is it possible to change the values of a custom attribute (adm-CustomAttributeTextMultiValue4) when selecting a value from another custom attribute (adm-CustomAttributeText1). For ... , 2Latijn, 3Latijn, etc... Is this possible? Sincerly Hilmi Emre Bayat

asked Aug 26, 2019 by hilmiemrebayat (510 points)
0 votes
1 answer

Using the built in 'Deprovision' Custom Command, I would like the person that is trying to Deprovision a user (Help Desk member) be asked who (from a list of existing active ... to leave the question 'blank', which means that no one gets access to the mailbox.

asked Apr 22 by RayBilyk (480 points)
0 votes
1 answer

So we have a new domain , lets say @def.com. It's within our primary domain @abc.com...this was done due to a company split. What changed for our users were their ... operational. LDAP Server unavailable" If I use my @abc.com, it works. Please advise. thanks

asked Oct 1, 2013 by MeliOnTheJob (10.6k points)
0 votes
1 answer

We are evaluating the product and would like to let users of AD to change password in self service page. We would like to set a 90 days change password policy, ... self service page? Is it achievable (with customization and batch program)? Thanks in advance.

asked Apr 27 by eric (250 points)
2,183 questions
1,948 answers
5,392 comments
5,309 users