Forum Search:
Forum.Brain-Cluster.com: Brain Cluster Technical Forum
Ultimate forum for Technical Discussions

Home » Microsoft » Windows Server » Active Directory » AzMan/ADAM store permissions
AzMan/ADAM store permissions [message #157017] Mon, 29 June 2009 10:37 Go to next message
M  is currently offline M  United Kingdom
Messages: 214
Registered: June 2009
Senior Member
Firstly, I'm not sure this is the best place to be asking this
question, so if you know of a better location then please let me
know.

I've recently configured an ADAM instance to hold an AzMan
application
store to authorise my users to perform specific actions within my web
app. This works just great and everyone is happy. That's the good
news. The bad news is that whilst managing the store locally on my PC
I decided (based on lack of information) to delete the store rather
than close it through my AzMan snap-in. The result? Not entirely
unexpected as it deleted the store from ADAM and hence stopped all
authorisation requests. It took me an hour to rebuild the store as
backups were not what they should have been (that's another issue).

So on to my question: Is it possible to grant some administrator
users
access to a store, but amend their permissions so that they can not
delete it? I would envisage that another administator user still
remain defined who does have permissions, but that this account would
be a special setup and not a day to day account.

Regards,

Mike
Re: AzMan/ADAM store permissions [message #157649 is a reply to message #157017] Fri, 10 July 2009 13:35 Go to previous message
Joe Kaplan  is currently offline Joe Kaplan  United States
Messages: 88
Registered: July 2009
Member
You multi-posted. I responded in the aspnet security group.

--
Joe Kaplan-MS MVP Directory Services Programming
Co-author of "The .NET Developer's Guide to Directory Services Programming"
http://www.directoryprogramming.net
"<M>" <m_dinnis@hotmail.com> wrote in message
news:602e29c5-ca58-447e-bc26-201575e2e311@k8g2000yqn.googlegroups.com...
> Firstly, I'm not sure this is the best place to be asking this
> question, so if you know of a better location then please let me
> know.
>
> I've recently configured an ADAM instance to hold an AzMan
> application
> store to authorise my users to perform specific actions within my web
> app. This works just great and everyone is happy. That's the good
> news. The bad news is that whilst managing the store locally on my PC
> I decided (based on lack of information) to delete the store rather
> than close it through my AzMan snap-in. The result? Not entirely
> unexpected as it deleted the store from ADAM and hence stopped all
> authorisation requests. It took me an hour to rebuild the store as
> backups were not what they should have been (that's another issue).
>
> So on to my question: Is it possible to grant some administrator
> users
> access to a store, but amend their permissions so that they can not
> delete it? I would envisage that another administator user still
> remain defined who does have permissions, but that this account would
> be a special setup and not a day to day account.
>
> Regards,
>
> Mike
Previous Topic:Add Users to DomainADM Grup in other domain - WP
Next Topic:filter out domain user accounts without email addresses
Goto Forum:
  


Current Time: Wed Oct 18 01:34:48 EDT 2017

Total time taken to generate the page: 0.06683 seconds
.:: Contact :: Home ::Sitemap::.

Powered by: FUDforum 3.0.0RC2.
Copyright ©2001-2009 FUDforum Bulletin Board Software