
Managing groups and user accounts
25
Managing groups
You can reduce the time that you spend managing user accounts by creating groups of similar user accounts and
assigning shared properties, such as software configurations or IT policies, to the group. Properties that you assign
to a group are assigned to all user accounts in the group.
You can assign properties to user accounts and administrator accounts at the individual level, group level, or domain
level. The BlackBerry® Administration Service applies properties to user accounts and administrator accounts using
the following hierarchy:
•
The properties at the individual level override the properties at the group level.
•
The properties at the group level override the properties at the domain level.
After you add a user account or administrator account to a group, you can override the properties that you configured
for the account at the group level or domain level by changing the properties at the user account level.
If you remove a user account or administrator account from a group, the account name remains in the global users
list but it does not appear in the group list.
You can either create user-specific groups and assign roles to those groups or use the default user groups that contain
pre-existing roles.
If you are managing a large number of groups (over 3000) using the BlackBerry Administration Service in a single
domain, your organization's environment might experience a performance impact.
Using default groups to manage user accounts and administrator accounts
The BlackBerry® Enterprise Server installation includes default groups that have preconfigured administrative roles.
You can use the default groups in your organization's environment instead of creating specific administrative groups.
Each default group consists of a set of preconfigured rules which specify the information that administrators can
view and the tasks that they can perform using the BlackBerry Administration Service and BlackBerry Monitoring
Service.
The default groups ensure users without administrative privileges cannot escalate their permissions, for example,
junior administrators cannot escalate their roles to senior administrator roles.
Default group
Description of the default group
Administrators
This is a preconfigured group for BlackBerry Administration Service
administrators. This groups has the permissions assigned to the Security
role.
Administrators in this group are responsible for ensuring all Junior Helpdesk
administrators are added to the Junior Helpdesk group.
Administration Guide
Managing groups and user accounts
242
Содержание PRD-10459-003 - Enterprise Server For IBM Lotus Domino
Страница 1: ...BlackBerry Enterprise Server for IBM Lotus Domino Version 5 0 Service Pack 3 Administration Guide ...
Страница 2: ...Published 2011 09 16 SWDT487521 1597421 0916011550 001 ...
Страница 22: ...38 Provide feedback 415 39 Legal notice 416 ...
Страница 227: ...11 Click Save all Administration Guide Assign software tokens to a user account 225 ...