This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Delegate Full Access but prevent assigning of additional Access Templates

Hi,

In my company, I have delegated Full Access (all objects) to several Organizational Units in AD - I recently noticed this also allows admins to assign additional Access Templates to allow other users to have access to that same area. Is there any way I can prevent this from happening? I don't mind them seeing the existing config or the templates themselves, but they should not be able to assign or remove any Access Templates. I already tried blocking class "Access Templates" but that didn't seem to help (guess that only locks out modifying the templates themselves). Couldn't find the option for denying (un)assigning templates or policies etc.

Thanks!

Parents
  • Hi,

    Thanks for the comments/suggestions.

    I indeed granted read-only access to the Policies for our admins, just to give them insight - this allows them to review the Policy settings, but now has a negative side effect in that, combined with Full Access to All objects, it also allows them to link policies.

    The team is native domain admin, so wanted to give them to most rich experience in AR as well, hence the "full access - all objects". I will look into just adding specific permissions. I agree that's neater, but was more from a convenience perspective I chose that method. Helpdesks do have fine grained access.

    Thanks again!
Reply
  • Hi,

    Thanks for the comments/suggestions.

    I indeed granted read-only access to the Policies for our admins, just to give them insight - this allows them to review the Policy settings, but now has a negative side effect in that, combined with Full Access to All objects, it also allows them to link policies.

    The team is native domain admin, so wanted to give them to most rich experience in AR as well, hence the "full access - all objects". I will look into just adding specific permissions. I agree that's neater, but was more from a convenience perspective I chose that method. Helpdesks do have fine grained access.

    Thanks again!
Children
No Data