Jump to content

How to create a user that has full rights to only one admin group and cannot see other managed groups [KSC for Windows]


Recommended Posts

Advice and Solutions (Forum Knowledgebase) Disclaimer. Read before using materials.

In this scenario we will create an internal user "test-user" on KSC who has permission on admin group "Virtualized" only, while couldn't view nor manage admin groups "servers" and "workstations".

Step-by-step guide

1. Take a backup from KSC admin server in order to make sure that incorrect changes will not impact your KSC.
2. Login to KSC admin server using admin account and go to KSC admin server →  Monitoring → Administration server →  Configure functionality displayed in user interface →  check the box Display security settings section.
3. Close KSC admin console and re-open it again in order to apply the feature.
4. Go to KSC admin server →  server properties →  security →  + internal user.
5. Don't assign Roles to the created user and only assign Rights.
6. The assigned Rights should be allow-all except Management of administration groups as per below.

image.thumb.png.2036ae4a88ee4f6bd7fb03b261375589.png
7. Go to Managed devices →  properties →  security →  uncheck inherit settings →  assign the right to the user as per below.

image.thumb.png.5e92ca6c75a33849d5990e8d2e70e41a.png
8. For admin groups that the user will not manage (e.g. servers in this scenario).

image.thumb.png.9ca5b3be9c7942e216b8bba758495bb5.png
9. For admin group that the user will manage (e.g. virtualized in this scenario).

image.thumb.png.4accf8e9143ca6f63c16972ae7a359aa.png
10. Disconnect from KSC admin server and login to KSC console using the created user and you will find that he has access to only virtualized admin group as per below.

image.thumb.png.16bde6c8148dee63ad5005ffa8b297af.png

 

image.thumb.png.8c77140fe0e36e47787e960000cf55e1.png

image.png

image.png

Link to comment
Share on other sites

Please sign in to comment

You will be able to leave a comment after signing in



Sign In Now


×
×
  • Create New...