When you apply an Access Template (as described in Applying Access Templates), Active Roles creates an Access Template link that stores information about:
-
The Access Template used for giving the permissions.
-
The directory object on which the Access Template is applied.
-
The user or group (Trustee) to whom the permissions are assigned.
If needed, you can modify the link via the Active Roles Console.
TIP: For more information about Access Template links, see Access Template link management in the Active Roles Feature Guide.
To view or modify Access Template links in which a given Access Template occurs
-
Right-click the Access Template, and click Links.
-
In the Links dialog, do the following:
-
To create a new link, click Add and follow the steps in the Delegation of Control Wizard to apply an Access Template. For more information, see Applying Access Templates.
-
To delete a link, select it from the list and click Remove.
-
To view or modify the inheritance and synchronization settings for a link, select the link and click View/Edit.
-
To change the synchronization setting for a link, select the link and click Sync to AD or Desync to AD.
-
To remove or restore the effect of a link, select the link and click Disable or Enable, respectively.
-
To view or modify Access Template links on a given object
-
Open the Active Roles Security dialog for the object with one of the following methods:
-
Right-click the object, and click Delegate Control.
-
Right-click the object, and click Properties. Then, on the Administration tab in the Properties dialog, click Security.
-
-
In the Active Roles Security dialog, do the following:
-
To create a new link, click Add and follow the steps in the Delegation of Control Wizard to specify permission settings on the object by using an Access Template. For more information, see Applying Access Templates.
-
To delete a link, select it from the list and click Remove.
-
To view or modify the inheritance and synchronization settings for a link, select the link and click View/Edit.
-
To change the synchronization setting for a link, select the link and click Sync to AD or Desync to AD.
-
To remove or restore the effect of a link, select the link and click Disable or Enable, respectively.
-
To view or modify Access Template links for a given user or group
-
Right-click the user or group, and click Delegated Rights.
-
In the Delegated Rights dialog, do the following:
-
To create a new link, click Add and follow the steps in the Delegation of Control Wizard to specify permissions for the user or group by using an Access Template. For more information, see Applying Access Templates.
-
To delete a link, select it from the list and click Remove.
-
To view or modify the inheritance and synchronization settings for a link, select the link and click View/Edit.
-
To change the synchronization setting for a link, select the link and click Sync to AD or Desync to AD.
-
To remove or restore the effect of a link, select the link and click Disable or Enable, respectively.
-
NOTE: Consider the following when managing Access Template links:
-
By default, the Active Roles Security dialog for an object lists all the links that determine the permission settings on the object, regardless of whether a link was created on the object itself or on a container or Managed Unit that holds the object. To change the display of the list, clear the Show inherited check box.
-
In the Active Roles Security dialog, only direct links can be removed, that is, a link can be removed if the link was created on the object itself (not inherited from a container or Managed Unit). Only direct links are displayed when you clear the Show inherited check box, so you can delete them by clicking Remove.
-
In the Active Roles Security dialog, the Remove button is available only on direct links. When you need to delete links, it is advisable to manage this by using the Links command on the Access Template or by using the Delegated Rights command on the Trustee (user or group).
Alternatively, you can delete a link by using the View/Edit option. Select the link and click View/Edit. Then, click Properties next to the Access Template box. After that, on the Administration tab, click Links. Finally, delete the link from the Links dialog.
-
In the Active Roles Security dialog, the Sync to AD button is available only on direct links. When you need to change synchronization status of a link, it is advisable to manage this by using the Links command on the Access Template or by using the Delegated Rights command on the Trustee (user or group).
Alternatively, you can change the synchronization status of a link by using the View/Edit option. Select the link and click View/Edit. Then, on the Synchronization tab, select or clear Propagate permissions to Active Directory.
-
Clicking View/Edit displays the Properties dialog for the selected link. This dialog can be considered as a focal point for administration of all elements of the link. Thus, from the Properties dialog, you can access the properties of the directory object, Access Template and Trustee that are covered by the link, view or modify the settings found on the Inheritance Options and Permissions Propagation pages in the Delegation of Control Wizard, and enable or disable the link.
-
You can also manage Access Template links on the Links or Active Roles Security tab in the Advanced Details Pane, which allows you to perform the same tasks as the Links or Active Roles Security dialog, respectively. Right-click a link or a blank area on the tab, and use command on the shortcut menu. The Links tab is displayed when you select an Access Template. Otherwise, the Active Roles Security tab is displayed. To display the Advanced Details Pane, check Advanced Details Pane on the View menu. For more information, see Advanced pane in the Active Roles Feature Guide.