|
| ZCS Administrator's Guide Network Edition 6.0.8 |
Frequently requested access rights are described below. The steps to set up an administrator to manage multiple domains are described in this section.To have one domain administrator manage more than one domain, you assign the rights to manage individual domains to the administrator account or administrator group.For example, to set up domanadministrator1@example.com to manage domainexample1 and domainexample2.com. Create a new administrator account on one of the domains to be managed.
1. Click New>Administrator and create the administrator account on one of the domains to be managed (domainexample1.com)
3. Click Next to configure the grants for this domain. When the views are selected, the rights associated with these views automatically display on the Configure the Grants dialog.Click Next. The informational box shows the grants were created.Click OK in the Informational window.
• Select the target type as domain
• Right Name type, adminConsoleAccountRights. Is Positive Right should be selected.
• Click Add and More
• The Add ACE page displays again and the Right Name field is empty. Type, adminConsoleDLRights and click Add and More
• After the last right, click Add and Finish. The Configure the Grants dialog displays these rights associated with the target domain. If you are adding another domain to manage, click Add and More. Repeat Step 4. If not, click Finish.To assign a user to manage a distribution list, you create a distribution list and enable Admin Group, select the view, grant the distribution list rights, add the user to the list and make that user an administrator.
• Check Admin Group
• Go to the Admin Views tab and check Distribution List View so the admin can view the distribution list.
• Click Save.
Target Type This domain right displays user account list that the administrator can select from to add to a distribution list. To create delegated administrators who only change passwords, you create the admin or admin group, select the views and grant the taskSetPassword combo right.
• Account List view to be able to select accounts to change passwords
• Alias List view to be able to find users who use an alias instead of account name.
2. The Configure the Grants page displays recommended grants for the views you have chosen. For Change Password rights, do not configure these grants. Select Skip. Click Add to add the following right:
Target Type
Target Type To prevent administrators from viewing an account with a domain or distribution list, assign the Is Negative Right to the account.You can expand the domain administrator role to be able to view and change the class of service (COS) assigned to a user. To add the rights to manage the COS for a domain, add the following rights to the domain administrator account or domain administrator admin group.
Target Type This domain right displays the COS information in the user account’s General Information page. Verb: WriteAR Target: domainThis role creates a delegated administrator role that can run the Search Mail tool to search mail archives or live mail for accounts. This also allows the administrator to create, abort, delete, purge or get status of a cross mailbox search request.
Target Type adminConsoleCrossMailboxSearchRights For full functionality, this role includes the ability to create new accounts so that the admin can create the target mailbox to receive the search results. If you do not want this role to have the ability to create accounts, grant the following negative right as well.
Target Type If you want this admin to also view the target mailbox with the results of the cross mailbox search, grant the right to view that mailbox only.
Target Type cross mailbox search target account name
Target Type server name or domain address adminConsoleAccountsZimletsTabRights server name or domain address
Target Type server name or domain address This role creates a delegated administrator that can access all the searches saved in the administration console Navigation pane, Search section.
Target Type adminConsoleSavedSearchRights server name or domain address This role creates a delegated administrator that can access the Server Status page. In addition to granting this right, you must also select the Admin View, Global Server Status View.
Target Type adminConsoleServerStatusRights
|
| ZCS Administrator's Guide Network Edition 6.0.8 |