Grant Rights To Administrators; Grant Permissions To Administrators; Permission Rules; Part 3: Database Security - Symantec ALTIRIS DEPLOYMENT SOLUTION 6.9 SP4 - V1.0 Manual

Table of Contents

Advertisement

Permission Rules

Part 3: Database Security

Deployment Solution

Grant Rights to Administrators

1.
In the Deployment Console, click Tools > Security.
2.
Select a user or Group and click Rights.
3.
Enable the rights you want granted.

Grant Permissions to Administrators

1.
Right click a Computer, Computer Group, or Job and select Permissions.
2.
Select a user or group and enable or disable the permissions you want granted.
Permissions received through different sources may conflict with each other. The
following permission rules determine which permissions are enforced:
Permissions cannot be used to deny the user with administrator console rights
access to use any console objects or features.
User permissions take precedence over Group permissions.
Deny overrides Allow. When a user is associated with multiple groups, one group
could be allowed a permission at a particular level while the other group is denied
the same permission. In this scenario, the permission to deny the privilege is
enforced.
Permissions do not flow down an object tree. Instead, the object in question looks in
the current location and up the tree for the first permission it can find and uses the
same.
If a console user does not have permissions to run all tasks the job contains, the
user is not allowed to run the job.
Securing your Deployment Database is tied directly to securing the account you use to
connect to the database.
Deployment Server requires only one account to have non-public access to the database
(the
Service Account
(page 203)). This account should be secured by a central
Deployment or domain administrator.
If you follow this process outlined in this document to create accounts and separate
privileges, you can greatly reduce the risk of your database being compromised.
Example
Your domain or central Deployment administrator creates a new domain-level account
with no interactive login, file system ownership of a single folder (Deployment Share),
and ownership of the Deployment Database. The password is provided to run the
Deployment Solution services and is stored securely.
No additional Deployment administrators need this password, and an intruder would
need to compromise a higher level administrator account in order to access these
credentials.
Securing Deployment Solution
207

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

Altiris deployment solution 6.9 sp4

Table of Contents