Create Provisioned Group for Administrators
You must create a provisioned group for administrators to ensure that you can enforce administrator rights. After you have created a provisioned group, make sure that you apply the provisioned group to a provisioning policy . Group provisioning policies preserve the integrity of your local group accounts.
To Create a Provisioned Group for Administrators
- From the Arellia Security Manager Console, go to the Policies tab.
- Navigate to Policies /Â Arellia / Local Security / Resources / Provisioned Groups.
- Right-click Provisioned Groups and click New / Provisioned User Groups or click the New button and choose Provisioned User Groups.
- In the New Provisioned Group window under Settings / Account Name, click Standard and choose Administrators.
- To enforce exact membership (exact membership ensures that the correct resources are always in the group, but doesn't enforce any other resources) in the Administrators Group, check Exact membership.
- To include the primary user (a primary user is the user that logs on most frequently to a particular machine), check Include primary user.
- Under Group Membership, go to the Include tab. Select Built-in users. Always include the Built-in Administrator Account.
You can include or exclude the following resources:
Include or Exclude Resources
Every resource that you add under the Include tab will ALWAYS be included in the group. Every resource that you add under the Exclude tab will NEVER be included in the group.
- Built-in users
- Domain groups
- Users