Published: 15/06/2018
Applies to: Cayosoft Administrator 5.x or later.
Summary:
When you create a new Web Administrator role, you can define which actions will be available for the certain group of people or trustees.
If you want to make some attributes to appear read-only on a form, or even hide those attributes, you can do that by configuring Attribute Policies.
This article will help you setup a delegation role and attribute policy, so your delegated administrators will have read-only access to the User Properties action.
Make read-only all controls on User Properties form
This is step-by-step instructions how to make all controls read-only on User Properties form using Attribute Policy. Same steps can be applied on other forms: just change policy scope to use another web query and actions on the step 7.
Note: It is assumed that you have already created a role with necessary trustee permissions in HOME > CONFIGURATION > Roles > Web Administrators. For more details on how to create a new web administrator role please refer to documentation here: https://www.cayosoft.com/documentation-role-based-delegation-attribute_security/#_Delegating_the_Web_Administrators_Role
- Open Cayosoft Administrator Console
- Navigate to Web Portal
- Click Attribute Policies
- Click the button Add Attribute Policy in the upper right corner
- Enter the name of the new policy
- Expand the Policy Details of the new policy
- If you need the policy to be applied to everyone who is using Cayosoft Web Interface leave radio button Policies Applied to everyone selected. Otherwise, select Policies applied only to specific Trustees, then click Add button and select required users or groups.
- Click Add Scope at the bottom right of the Policy Scope section
- On the Specify Policy Scope dialog, do the following:
a) Select the Active Directory admin unit in the first column (you can select any others AD unit if needed)
b) Select the AD Users Web Query in the second column (you can select additional web queries if needed like, AD User Templates, AD Users (Inactive), etc)
c) Select Properties in the third column
d) Click OK - Click the scope you just added to select it. Attribute policy setting list will be populated with attributes, available on the selected form(s).
- Select Enable multi-selection checkbox
- Click on topmost checkbox to select all attributes
- Click on Edit Policy button
- Select first checkbox for the Is Read-only option to enforce the read-only setting to ON or OFF
- Select second checkbox for the Is Read-only option to set it to ON for all selected attributes
- Click OK to close the dialog
- Save Changes
Related Articles
More information about Attribute Policies and Role Based Delegation you can get from our documentation articles:
Overview of Role Based Delegation
Overview Attribute Policies
KB20180606-1 How to change License plans visibility in Web Interface
Comments
0 comments
Please sign in to leave a comment.