Configuration of Self-Service
Overview
CayosoftWeb Portal provides a Self-Service container. This container includes a set of Web Queries:
NOTE: Active Directory Self-Service web queries require connected users to be from the managed domains.
My AD Groups, My AD Users, My AD Users (expiring): display the Active Directory users and groups managed by the user who is running the query. Each user will see only the objects that they manage.
My Office 365 Groups, My Office 365 DLs: display the Office 365 groups managed by the user who is running the query.
My AD Memberships: users can see their membership in Active Directory groups and can add themselves to groups that are published for discovery. Learn more in: Configuration of Group Publishing.
My Cloud Memberships: My Cloud Memberships web query displays the Microsoft 365 groups for which a user is a member.
My Company Directory: users can find the phone numbers of their colleagues and some other business information: office, department, title.
My Pending Tasks, My Request Status: display the work items for approval and certification that are assigned to the user who is running the query or checking their status.
My Teams: display the Teams managed by the user who is running the query.
Configure Role-Based Delegation for Self-Service
Follow the steps below to create Group Self-Service Role:
In the Cayosoft Administrator console, navigate to Configuration > Roles > Web Administrators.
Click Add Delegation Rule.
In the Name field of the new rule type Self-Service.
Below the Trustee list, click Add.
Click Search to return a list Active Directory Groups.
Select the group that represents the users who will be allowed to manage their users and groups.
Click OK.
Below the Trustees Permissions, click Add Scope - the Specify Policy Scope dialog box appears.
In the All Admin Units, check Self-Service.
In the All Web Queries, check My AD Groups.
-
In the All Actions, check Properties, Suspend Group, Undo suspend.
NOTE: There are multiple Actions named Properties and Undo Suspend. Place the mouse over each until you see the tooltip Group Properties appear, that is the correct action to check.
Click OK at the bottom of the Specify Policy Scope dialog,
Open the Object Pickers section.
Check AD Groups and AD Users.
Click Save changes.
Assign a user to manage a group
Logon to the Web Portal as an administrator who can manage groups.
Expand Active Directory > AD Groups.
Enter the name of the group being assigned to the user in the search field and click Search Objects.
Click the check-box to the left of the group name and click the Properties web action on the right.
At the top of the Modify Group dialog, click Managed By.
Click Change.
In the search field, enter the first few letters of the group manager’s name then click Search Objects.
Click the checkbox to the left of the group manager’s name then click OK.
In the Modify Group dialog box click Update.
Configure Role-Based Delegation for My Company Directory
Follow the steps below to create the My company directory role:
In the Cayosoft Administrator console, navigate to Configuration > Roles > Web Administrators.
Click Add Delegation Rule.
In the Name field of the new rule, type Self-Service.
Below the Trustee list, click Add.
Click Search to return a list Active Directory Groups.
Select the group that represents the users who will be allowed to see the employees' contact information.
Click OK.
Below the Trustees Permissions, click Add Scope - the Specify Policy Scope dialog appears.
In the All AdminUnits, check Self-Service.
In the All Web Queries, check My Company Directory.
Click OK at the bottom of the Specify Policy Scope dialog box.
Click Save changes.
Comments
0 comments
Please sign in to leave a comment.