Helpdesk and automated groups in AD
Group management and especially security group management is an important part in Rights Access Management. Big companies and distributed organizations have to deal with a huge number of groups an permissions. These enterprises often have local IT coordinators to support daily adminstration and standard issues. Unfortunately permission management is still troublesome.
You could
- Completly delegate AD user management
- Delegate automated group management only
Our customer, a company with 12 branches, decided for the second option. The company does the main user management in the headquarter. User objects are created by the HR department staff. An Identity Management sync solution pushes them to AD and updates most necessary attributes. But then it comes to permission management.
Permission Management: Helpdesk and automated security groups
The attribute for department is used for a self-updating department group. DynamicGroup provides an easy Query Builder to create attribute based groups.
The customer executes most standard and global permissions by the headquarter IT department.
But there are a lot of small companies that have been acquired by the customer in the last years as well.
These branches have local IT staff that takes care of special and local permissions as OU admins. They maintain specific permissions by themselves.
Local helpdesk and group automation
One example was a branch with a machine where people got access to via AD group permission.
This machine was only available to people with a certain value in their extensionAttribute5.
The local IT could create a security group with self-updating group memberships that added all users to that group, if they had extensionAttribute5 filled with “access_granted”
DynamicGroup Delegation
DynamicGroup can be used by “full” admins and delegates.
This enables distributed helpdesks or local IT departments to maintain automatic security groups in their OU.
For more detailled information about the software solution, please visit the product page of DynamicGroup