cancel
Showing results for 
Search instead for 
Did you mean: 

Basic admin rights in BOXI R3

Former Member
0 Kudos

Hi guys,

I imagine this is a commonly asked question with a very simple answer but I can't find any other related discussions...

I have three groups...

'Administrators'

'Admin Group'

'Standard Users'

The 'Administrators' group has our 'administrator' user, a super user with access to everything.

The 'Admin Group' is a group of users I want to grant basic admin rights (create user, change password, enable/disable user, delete user) to. These users should only be able to create/manage users in the 'Standard Users' group.

The 'Standard Users' group is a-ok.

So.... can someone tell me how to assign the following rights to our 'Admin Group'?

I want them to be able to:

1. Login to CMC.

2. Click 'Users and Groups'.

3. Edit existing users (enable/disable users, change password).

4. Create new users and assign them to the 'Standard Users' group.

And that is all. I don't need them to be able to do anything else. Just create and manage users in the 'Standard Users' group.

====

I've created an access level 'Admin Access'

And 'Granted' the following 'Included Rights'

Application > CMC > General Rights for CMC > 'Log on to the CMC and view this object in the CMC'

System > User > 'Add objects to folders that the user owns' + 'Add objects to the folder' + 'Change password for the users that the user owns' + 'Change user password' + 'Delete objects' + 'Delete objects that the user owns' + 'Edit objects' + 'Edit objects that the user owns'

System > User Group > 'Add objects to folders that the user owns' + 'Add objects to the folder'

--- Now, I've added the 'Admin Access' access level to the 'Admin Group' and I've made 'Admin Group' a member of 'Standard Users'.

I've created a select group of users and only added them to 'Admin Group' but I fail at the first hurdle... they can't even log in the the CMC!!

====

Any help would be greatly appreciated... please forgive my complete lack of knowledge.

Regards,

Kahli.

Accepted Solutions (1)

Accepted Solutions (1)

former_member185603
Active Contributor
0 Kudos

Unfortunately you cannot restrict in CMC for each area in 3.1. But where as in 4.0, you have an option for delegated admin users and also have an option to hide some of the options in CMC.

Check this KB for user creation rights.

1475911  - XI 3.1 Delegated Administrator Security for User Creation

Former Member
0 Kudos

Thanks for the swift response, Jawahar.

All sorted now, the link was a great help.

Answers (1)

Answers (1)

FrederiqueLB
Advisor
Advisor
0 Kudos

Any reason why you add Admin Group as a subgroup of Standard Users?

You can keep Admin Group on its own and still make it an admin group of Standard Users:

- In your Access Level, you'll have to add some rights under General (add objects, edit objects, change password, copy objects, view objects).

- In Users and Groups, add Admin Group as a principal of Standard Users group, and assign Admin Group access level.

- Add Admin Group as a principal at the top-level of all users to be able to create users.

It should be enough to permit Admin Group users to create users and assign them to Standard Users group.

Frederique

Former Member
0 Kudos

Thanks for getting back to me so quickly, Frederique.

All sorted now, your steps were very useful.