Karthik's Cloud Blog

ConfigMgr vNext Role Based Administration

Posted by karthickvaranasi on Thursday, August 5, 2010

New Console Objects…

Administrative Users = Users and Groups that have admin rights in ConfigMgr

Security Roles = Role based permissions in ConfigMgr

Security Scopes = Securable Objects in ConfigMgr

Now lets take a quick glance on how it actually looks like:

We are
going to setup a Packaging role and see the console difference after.

1) Full console access for an Administrator

image

2) Select Security & Permissions –> Right Click add user or group

image

3) Select Packaging Group or user from AD and click next

image

4) add the user to the Application Deployment Role and click next

image

5) on the security scope screen select user can see all objects and click next. (We will limit this later)

image

6) on the summary screen click next

image

7) Click close on the confirmation screen

image

8) Our user has console access and is limited to applications only lets go one step further and limit which applications the users in this group can see by adding a security scope to the security role.

9) Right click the user we just added select Properties and click Security Scopes,  We are going to add a security scope we previously created.

image

10) Select the second radio button add our Custom Security Scope, Remove the default security scope and click apply

image

11) Below is a quick view of what you would see if you had access to all packages.

image

12) Below is a screenshot of what one of our Packaging team members consoles looks like.  As you can see the list of Packages have decreased due to our security scope that has been assigned to our security role.

image


Tags: configmgr vnext ; sccm vnext 

ConfigMgr & Intune MDM service Engineer


Karthik Varanasi Loading. . . ╔════════════════╗ ║████████████ 99.99% ╚════════════════╝

Categories

Make a Free Website with Yola.