Deployment Solution
206
Securing Deployment Solution
One major advantage of the Deployment Solution security model is that administrators
do not need to be granted explicit rights on any managed computers. All access is
filtered through the integrated role-and-scope based security in the Deployment
Console.
Example: if you grant an administrator rights to install software on a managed computer
in the Deployment Console, it does not allow him to log in to that computer and install
software. All actions must go through the Deployment Console.
Implementing a strong policy to manage the access granted to your Deployment
administrators protects managed computers from unauthorized access.
Deployment Console Security
By default, the Deployment Console can be used on your Deployment Server by any
user who possesses rights to log in and run applications. This works well in situations
where you already have policies in place to control server access, and you have a group
of administrators who will have full access to deployment functionality.
If you want to provide more granular access to configuration options, jobs, and
computers, you can enable security.
To enable security
You must add at least one user or group to enable security.
1. In the Deployment Console, click Tools > Security.
2. Add a new user or group. We recommend clicking AD Import and importing Active
Directory groups, as this simplifies rights management. The first user or group
added is granted administrator rights. Each additional user or group after the first
are granted no rights and must be assigned rights explicitly.
3. Security is automatically enabled after a user or group is added.
Additional users or groups can be added using this same method.
Manage By Exception
The Deployment Solution role and scope-based security model uses the concept of
managing by exception. To manage permissions, you make an assignment at a
container level that applies to most of the members of the container and you manually
add exceptions where needed.
We recommend planning administrator, computer, and job groups so that all permission
assignments can be made at the group level.
Rights and Permissions
The Deployment Console separates privileges into two categories:
Rights
Provide access to console settings, database connections,
domain accounts, and other options. Typically, you
restrict most rights to one or more main administrators.
Permissions
Controls access to jobs and managed computers. These
permissions are usually distributed across all
administrators who perform work in Deployment Solution.
Содержание ALTIRIS DEPLOYMENT SOLUTION 6.9 SP4 - V1.0
Страница 1: ...Altiris Deployment Solution 6 9 SP4 from Symantec Admin Guide ...
Страница 40: ...Deployment Solution 40 What is Automation z Which Automation Operating System Should I Use page 44 ...
Страница 144: ...Altiris Deployment Solution from Symantec User s Guide 144 ...
Страница 371: ...Altiris Deployment Solution from Symantec User s Guide 371 ...