12.4 Configuring User Account Policies

12.4.1 Viewing the Current User Account Policies

  1. In Web Admin console, select Users tab to view a list of current iFolder users.

  2. Click the link for the user’s name to open the User page for that user account.

  3. You can view the following information below Policies:

    Parameter

    Description

    Account

    Specifies whether the user is currently allowed to log in to synchronize iFolders. You can select the check box to disable the User login.

    No of iFolder per users

    Specifies the maximum number of iFolder that a user can own. After Applying this policy, the user is limited to own a certain number of iFolders.The user who exceeds his or her usage limit receives an error message about the policy violation. If the limit is zero, the user cannot create any iFolders.

    Disk Quota

    Limit: Specifies the maximum space allotted on the server for this selected user.

    Used: Specifies the total space currently in use on the server for all iFolders owned by this selected user.

    Available: Specifies the difference between any space restrictions on the account and the space currently in use. If no quota is in effect, the value is No Limit.

    Effective: Effective space allocated on the server.

    File size

    Specifies the maximum total space (in MB) that a user’s iFolder file is allowed to use, across all iFolders the user owns. A user quota supersedes a system-wide quota, whether the user quota is larger or smaller than the system-wide quota. The user quota can then be limited, but not increased by a policy on an iFolder.

    IMPORTANT:Users cannot successfully synchronize files of a size that would cause a quota to be exceeded. If they try to do so, only part of the file is synchronized, resulting in data corruption.

    If the total space consumed by iFolder file is nearing an effective quota (system, user, or iFolder), the user should stop synchronizing files until one or more of the following tasks results in enough space to safely synchronize the user’s files in the iFolder where the file resides:

    • The system-wide quota, user quota for the iFolder owner, and the iFolder quota are modified as needed.

    • Files are moved from any of the iFolders owned by the user to another location where they no longer affect the effective quota, or files are deleted to clear space.

    • Files are moved from the iFolder to another location where they no longer affect the effective quota, or its files are deleted to clear space.

    Excluded files

    Specifies to allow all file types or lists the file types to exclude from synchronization for the selected user’s account.

    The file manager files called thumbs.db and .DS_Store are never synchronized. You do not need to keep these files, and synchronizing them results in repeated file conflict errors. If you have not set any individual restrictions for this user, this field reports thumbs.db and .DS_Store as part of the system-wide file-type restrictions. After you set individual file-type restrictions for the user, the user’s settings are displayed instead. Even if the thumbs.db and .DS_Store restrictions are not displayed, they always apply; you cannot override them.

    Synchronization

    Specifies the minimum interval (in minutes) that a user’s client can check iFolder data on the server and iFolder data on local iFolders to identify files that need to be downloaded or uploaded. Longer interval limits are more restrictive than shorter ones.

    Interval: If a user policy is set, it overrides the system policy, whether the user’s interval is shorter or longer in value.

    Effective: Specifies the current synchronization interval. For example, if the user sets a synchronization interval that is less than (more frequent) than the system minimum, the system setting applies.

    The effective minimum synchronization interval is always the largest value from the following settings:

    • The system policy (default of zero (0)), unless there is a user policy set. If a user policy is set, the user policy overrides the system policy, whether the user policy is larger or smaller in value.

    • The local machine policy, or the setting on the client machine synchronizing with the server.

    • The iFolder (collection) policy.

    Encryption

    Specifies the encryption policy for the selected iFolder user.

    Sharing

    Specifies the sharing policy for the selected iFolder user.

12.4.2 Modifying User Account Policies

  1. In Web Admin console click the user name link listed under User’s tab to open the user page

  2. On the User page opened for that user account, you can select or deselect the following:

    Parameter

    Description

    Account

    Select the Disable User Login check box to disable the account for login.

    Deselect the value to enable the account for login.

    If the user is logged in when you make this change, the user’s session continues until the user logs out. The policy takes effect the next time the user attempts to log in to the account. To have the lockout take effect immediately, you must restart the Apache services for the iFolder server, which disconnects all active sessions, including the user’s session.

    Default Value: Enabled, Yes

    No of iFolder per users

    Specifies the maximum number of iFolder that a user can own. After Applying this policy, the user is limited to own a certain number of iFolders.The user who exceeds his or her usage limit receives an error message about the policy violation. If the limit is zero, the user cannot create any iFolders.

    Select Limit to enable the iFolder per users limit, and specify the number in the field.

    The policy setting does not affect the number of iFolders that the user already owns. If the number of iFolders owned by the user already exceeds the limit that you set, he or she can still own those iFolders.

    User level policy overrides LDAPGroup level and system level policy.

    Default Value: Disabled, no value set

    Disk Quota

    Specifies the maximum space allotted on the server for this selected user.

    Deselect Limit if there is no individual user quota, or to accept the system-wide quota for the selected user account.

    Select Limit to enforce a user quota, then specify the total space quota (in MB) for the selected user account.

    File size

    Specifies the maximum total space (in MB) that a user’s iFolder data is allowed to use, across all iFolders the user owns for the selected user account.

    Deselect Limit if there is no individual user quota, or to accept the system-wide quota for the selected user account.

    Select Limit to enforce a user quota, then specify the total space quota (in MB) for the selected user account.

    If you enable a user space limit that is less than a user’s current total space for iFolder data, the user’s data stops synchronizing until the data is decreased below the limit or until the quota is increased to a value that is larger than the user’s total space consumed.

    Default Value: Disabled or the system-wide quota if it is set.

    Excluded Files

    You can restrict some file types for this user, then specify the exclusion filters that determine the file types that can be synchronized for the user account.

    To add a file extension to exclusion filter, type the extension (such as *.mpg), then click Add to apply the filter.

    To exclude a file type from the restricted file types, select the check box adjacent to the file type, then click Allow.

    Default Value: The System-wide settings.

    Synchronization

    Select the check box to enable a minimum synchronization interval, then specify the minimum interval (in minutes). For example, a practical value is 600 seconds (10 minutes).

    Deselect the check box to set no synchronization interval or to accept the system-wide setting for the user account. If no value is set for system-wide or user policies, the value reported is No Limit.

    Default Value: Disabled, System-wide policy.

    Encryption

    You have two options for encryption to select from: On and Enforced

    On: Select On to enable Encryption. With this, user is allowed to set encryption policy for his or her iFolder files. User will have the control over the sharing of his iFolder data.

    Enforced: Select Enforced to enable encryption policy for the iFolder files of the selected user account.

    IMPORTANT:This option is enabled only if the system level encryption policy is set to On.

    Sharing

    You have three options for Sharing to select from: On, Enforced and Revoke.

    On: By default, iFolder sharing is enabled. Select On to disable sharing for the selected user. After applying this policy, user is not allowed to share his or her iFolders with others. However, you can still change the policy settings at iFolder level.

    Enforce: Select Enforce to enforce the policy set for the selected user. After applying this policy, the user cannot share his or her iFolders with others.

    Revoke: Select Revoke to remove the shared members of all the iFolders that belong to the selected user.