By default, on installing Active Roles, all users are allowed to log in to the MMC interface. To manage the MMC interface access for a user, you must configure the options using Configuration Center | MMC Interface Access| Manage settings. Selecting this option restricts all non Active Roles Administrators from using the console. All delegated users are affected, however, it does not apply to Active Roles Administrators.

To be able to log in to the MMC interface, the user must be delegated with the User Interfaces access rights on the User Interfaces container under Server Configuration. User Interfaces Access templates that provide the access rights are available as part of the Active Roles built-in Access templates in the User Interfaces container.

To delegate the control to users in the User Interfaces container you must apply the User Interface Access Template

  1. In the console tree, expand Active Roles | Configuration | Server Configuration.
  2. Under Server Configuration, locate the User Interfaces container, right-click it, and click Delegate Control.
  3. On the Users or Groups page, click Add, and then select the users or groups to which you want to delegate the control. Click Next.

  4. On the Access Templates page, expand the Active Directory | User Interfaces folder, and select the check box next to User Interface Management-MMC Full control.
  5. Click Next and follow the instructions in the wizard, accepting the default settings.
  6. After you complete these steps, the users and groups you selected in Step 3 are authorized to log in to the MMC interface.

  7. Click OK to close the Active Roles Security dialog box.