A Provisioning Policy includes the following:
- Users that can be provisioned
- Groups that can be provisioned
- Provisioning interval
When you apply the Removing Administrator Rights Policy, after the initial removal of Administrator Rights, the interval should be anywhere between 1 to 7 days (if the end user is not an administrator). However, if the end user is an administrator, after the initial removal of Administrator Rights, the interval should be much shorter (anywhere from 30 minutes to 4 hours). To ensure that the removal of administrator rights occurs, validate the policy by going to Local Administrators Reports .Apply a provisioned group to target computers after you have created a provisioned group. When you provision the Administrators Provisioned Group, remember that you want to run the policy on a schedule that will ensure the strictest integrity of your local group accounts.
To apply a provisioned group, do the following steps:
- From the Arellia Security Manager Console to the Policies tab.
- Navigate to Policies > Arellia > Local Security > Policies.
- Right-click Policies > New > Client Scheduled Tasks > Local Security Scheduled Client Task.
- Select Local Security Provision Command.
- From Provision Administrator Group select Provisioned Groups.
- Create a New Schedule for the provisioning policy.
- Enable the policy, by ensuring the green toggle is on.
- Add Target computers to the Policy.
- Save the policy. The Administrators Group will be applied on the set schedule.