Answer the question
In order to leave comments, you need to log in
Are there corporate solutions for convenient distribution of rights to DFS?
Available: AD, DFS, with folders divided by management and further by departments, and further by sub-departments (not always).
For example, the directory branch structure "IT Management" -> "Development Department" -> "Project Alpha"
Each department has its own chief and deputy, who are the formal owners of their resource and can grant access to employees. In the security properties of each folder, an AD group has been added, for example "Project Alpha (reading)"
How distribution of access is implemented now:
For example, intern Pupkin wants to get access to the Development Department (and only).
1 He writes a service for access, indicates the type of access (for example, reading)
2 Brings Tapkin (the owner of the resource, the development department) for signature.
3 With a signed service, it is sent to the IT support department where its application is checked and accepted for processing
4 The application is transferred to the engineer responsible for access, who adds the user to the appropriate access group
As you wish:
Something like pipelined access processing. A system in which the administrator specifies key directories and employees. And Pupkin's application will be sent electronically for signature to Tapkin or his deputy and immediately after certification, it will be automatically executed.
Answer the question
In order to leave comments, you need to log in
Didn't find what you were looking for?
Ask your questionAsk a Question
731 491 924 answers to any question