Custom Command Question

General discussion of using Adaxes for Active Directory management and administration

Custom Command Question

Postby BeaconlightBoy » Wed Jan 11, 2012 2:31 pm

I have noticed, and maybe I am doing something wrong, but it appears even though i have a Security Role that deny's full control to all objects (your blind role modified), users can still run custom commands via the web interface. But, if i deny them the ' Execute all custom commands' in any other rule it works like its supposed to. i don't understand. Why doesn't the full control cover executing custom commands.

the problem is that everytime we add a new rule, we don't want to go exclude it somewhere.
BeaconlightBoy
 
Posts: 12
Joined: Fri Aug 12, 2011 11:22 am

Re: Custom Command Question

Postby Eugene Pavlov » Thu Jan 12, 2012 12:42 am

Hello,

If you deny the Full Control permission for a user, the user will not be able to neither perform any operation in AD (including execution of Custom Commands), nor view any object in Active Directory. In your case, I think something is wrong with the user assignment. Could you send me a screenshot with the assignments of the role?

BeaconlightBoy wrote:the problem is that everytime we add a new rule, we don't want to go exclude it somewhere.

Do you mean Custom Command (not rule)? When you create a Custom Command, by default, users don't have the right to execute it. However, some built-in Security Roles (e.g. Help Desk) grant the Execute All Custom Commands permission. If you don't want users to be able to execute Custom Commands, just delete that permission from the Security Roles assigned to the users.
Active Directory Identity Management

Follow Adaxes in social networks
Image Image Image Image
User avatar
Eugene Pavlov
 
Posts: 401
Joined: Wed Apr 29, 2009 11:10 pm


Return to Active Directory Management with Adaxes

Who is online

Users browsing this forum: No registered users and 0 guests

cron