Submitting forms on the support site are temporary unavailable for schedule maintenance. If you need immediate assistance please contact technical support. We apologize for the inconvenience.
What are the minimum permissions required to allow delegated administrators to link Access Templates?
Description
You may wish to allow delegated administrators to create and link access templates without granting them ARS Administrators permission.
Resolution
In ARS MMC Console, select View | Mode and then select Raw Mode
Create a new Access Templates and add the following permissions to it:
All Classes – Write Control
Create a new Access Templates and add the following permissions to it:
All Classes – Read Control
Select the Access Templates container and grant the following permissions to the delegated administrators:
All objects - read all properties.
NOTE: This will allow your delegated admins vew all the Access Templates. If you want to limit the number of Access Templates visible to delegated administrators, apply the Special - Block Permission Inheritance Access Template to each Access Template container you want to hide.
Select the target domain and grant the following permissions to the delegated administrators:
All objects - read all properties
For each OU where the delegated administrators will apply access templates, delegate the following permission using Access Template created in Step 2:
All Classes – Write Control
For each OU where the delegated administrators need to view the applied Access Templates, grant the following permission using Access Template created in Step 3:
Your Request will be reviewed by our technical reviewer team and, if approved, will be added as a Topic in our Knowledgebase.
Recommended Content
Product(s):
Active Roles
7.4.3, 7.4.1, 7.4, 7.3.3, 7.3.1, 7.2.1
Topic(s):
Technical Solutions
Article History:
Created on: 11/16/2011 Last Update on: 5/25/2020
Author:
Daniel Bishop
Thank you for your feedback for Topic Request
Your Request will be reviewed by our technical reviewer team and, if approved, will be added as a Topic in our Knowledgebase.
Welcome to One Identity Support
You can find online support help for*product* on an affiliate support site. Click continue to be directed to the correct support content and assistance for *product*.
The One Identity Portal no longer supports IE8, 9, & 10 and it is recommended to upgrade your browser to the latest version of Internet Explorer or Chrome.