Dynamic Groups - Deny changes

Chaps.

We have Admins who have access to the MMC console and as such have the ability to change Dynamic group membership. Is there away to stop say AdminGroup1234 from being able to edit specific Dynamic groups? 

Thanks in advance  

Top Replies

Parents
  • Practically speaking, no as you have to be an AR admin to manage dynamic group membership rules.

    Here's some food for thought:

    It's one thing to allow I.T. folks to use the MMC console as their interface to AD via Active Roles.

    It's a HUGE risk to have too many people with administrative access to the Active Roles application itself.  i.e. you do not HAVE to be an AR admin to use the MMC.

    Here's a suggestion I have if you want to allow semi-delegated management of dynamic groups:

    Let's assume that you use the contents of certain virtual attributes that you setup for the purpose to control the membership of dynamic groups.  You could delegate access to the editing of those attributes and thus indirectly allow someone to manage dynamic group membership.  Maybe that's not your use case though.

    Maybe you can elaborate on your use case a bit?

  • Thanks mate. Yes that pretty much the line I want to go down with VA and use that already on many groups.  However what i was looking to stop was someone adding a new query or an explicit entry to the dynamic group. 

  • Think about what I said about AR admins though.  I have found over the years that customers hand out admin right to the AR application way too freely - often for political reasons and then find themselves in a jam because someone made an AR configuration change that affects the productivity of the delegated admins community.

Reply
  • Think about what I said about AR admins though.  I have found over the years that customers hand out admin right to the AR application way too freely - often for political reasons and then find themselves in a jam because someone made an AR configuration change that affects the productivity of the delegated admins community.

Children