Delegated Administration

NDS allows you to delegate administration of a branch of the NDS tree, revoking your own management rights to that branch. One reason for this approach might be that special security requirements require a different administrator with complete control over that branch.

Delegated administration is accomplished by

  1. Granting the Supervisor object right to a container.
  2. Creating an IRF at that container which filters the Supervisor and any other rights you want blocked.

WARNING:   If you delegate administration to a User object and that object is subsequently deleted, there will be no objects with NDS rights to manage that branch.



Previous | Next