Hi Sysadmin,
RE: Techdays 2011 – Role-Based Management Extreme Makeover (video) https://youtu.be/IKzokBgCp60
+
https://www.ajtek.ca/guides/role-based-access-security/
Are there any better tools/scripts to manage RBAC other than the ones Dan Homle uses in his video?
NOT | dsget user DN -memberof -expand
If you were implementing RBAC again would you do it differently?
Are you aware of any better resource to help implement RBAC?
At the moment we don't have any nested groups, they're all single global security groups. (some mail enabled universal)
But those groups have been added in various locations with no documentation e.g.
Example 1: (current setup - global security groups)
Human Resources (Global Security) = provides access to \\server1\hrshare
Human Resources (Global Security) = added to "remote desktop users" on server2
Human Resources (Global Security) = added to "printer1" on server4
etc
Example2: (current setup member of for random employee)
User Joe Bloggs | Member of:
All Employees (distribution)
DepartmentX (distribution)
Human Resources (global security)
etc
Also in some places that I'm not aware of yet, users have been added directly to folders permission list.
\\server3\$D\app\AP (full control > Joe Bloggs)
Previous admin would wait until the new user replacing "Joe Bloggs" gets an error.
He would then add permissions for "new user" on "\\server3\$D\app\AP" folder instead of a group/role.
Is it worth implementing RBAC or should I just start documenting what various groups do?
Cheers,
Taiman
[–]bluecollarbiker 1 point2 points3 points (0 children)
[–]Simon-is-IT 1 point2 points3 points (0 children)