Hello
i´m searching for a way to delegate decentralized admins to Change a regular Group into a dynamic Group.
Is there a way to do that?
Hello
i´m searching for a way to delegate decentralized admins to Change a regular Group into a dynamic Group.
Is there a way to do that?
Please take a look at KB82906. This article outlines the attributes that need to be granted access to in order to perform the conversion.
Thanks for the answer. I already tried that, but it did not work in our environment. The explicit deny did not work on some admin-groups - still dont know why.
I was told to try to find a way to prevent the decentralized admins creating dynamic groups that have over 5000 members. Do you have any advice doing it that way?
Thanks in advance.
just a guess. If jsmith is a memberOf AD\ARSADmins ("DSAdminitrators"), he will get all rights over AR Configuration (including Dynamic Groups) and FC - All Objects in All Managed Domains. AR Roles AT permissions is not checked against "DSAdministrator" including DENY.
Make sure, jsmith is not "DSAdministrator".
just a guess. If jsmith is a memberOf AD\ARSADmins ("DSAdminitrators"), he will get all rights over AR Configuration (including Dynamic Groups) and FC - All Objects in All Managed Domains. AR Roles AT permissions is not checked against "DSAdministrator" including DENY.
Make sure, jsmith is not "DSAdministrator".