B.3 ProxyRights Group Permissions

By default, whenever any of the components of File Dynamics are installed on a computer in a domain, the fdproxyrights universal security group is granted membership in that domain's Administrators built-in security group. This grants the product all of the necessary permissions to read and write attribute values on objects in the domain. This also eliminates the need for the Synchronize directory service data privilege to be granted to the fdproxyrights group on each domain controller in the domain.

IMPORTANT:If your organization's security policies do not allow for fdproxyrights to be a member of each domain's Administrators built-in security group in each managed domain, then you need to explicitly grant permissions and extend rights in Active Directory to fdproxyrights at the domain level of every managed domain. Please contact Micro Focus Technical Support for assistance when configuring these detailed permissions.

By default, whenever any of the components of File Dynamics are installed on a member server in a domain, fdproxyrights is granted membership in the built-in Administrators group on the member server.

On other servers in the domain that are hosting user or collaborative storage managed by File Dynamics, you must also grant fdproxyrights group membership in the built-in Administrators group. This is necessary because there are many storage management actions performed that require membership in this group regardless of the LSA privileges that the user has been granted—in particular, managing file shares and directory quotas.

Additionally, the other servers in the domain that are not hosting components, but are hosting user or collaborative storage, must have the rights and privileges described in the table above, along with Full Control share permissions. The easiest way of granting these rights and privileges is through Group Policy objects in Active Directory.

As explained in Setting Rights and Privileges on Managed Storage in the Micro Focus File Dynamics 6.5 Installation Guide, you must grant Full Control sharing and security privileges to the fdproxyrights group for each share that File Dynamics will manage.