Blackberry PRD-10459-003 Administration Guide - Page 244

Managing groups and user accounts, Managing groups

Page 244 highlights

Administration Guide Managing groups and user accounts Managing groups and user accounts 25 Managing groups You can reduce the time that you spend managing user accounts by creating groups of similar user accounts and assigning shared properties, such as software configurations or IT policies, to the group. Properties that you assign to a group are assigned to all user accounts in the group. You can assign properties to user accounts and administrator accounts at the individual level, group level, or domain level. The BlackBerry® Administration Service applies properties to user accounts and administrator accounts using the following hierarchy: • The properties at the individual level override the properties at the group level. • The properties at the group level override the properties at the domain level. After you add a user account or administrator account to a group, you can override the properties that you configured for the account at the group level or domain level by changing the properties at the user account level. If you remove a user account or administrator account from a group, the account name remains in the global users list but it does not appear in the group list. You can either create user-specific groups and assign roles to those groups or use the default user groups that contain pre-existing roles. If you are managing a large number of groups (over 3000) using the BlackBerry Administration Service in a single domain, your organization's environment might experience a performance impact. Using default groups to manage user accounts and administrator accounts The BlackBerry® Enterprise Server installation includes default groups that have preconfigured administrative roles. You can use the default groups in your organization's environment instead of creating specific administrative groups. Each default group consists of a set of preconfigured rules which specify the information that administrators can view and the tasks that they can perform using the BlackBerry Administration Service and BlackBerry Monitoring Service. The default groups ensure users without administrative privileges cannot escalate their permissions, for example, junior administrators cannot escalate their roles to senior administrator roles. Default group Administrators Description of the default group This is a preconfigured group for BlackBerry Administration Service administrators. This groups has the permissions assigned to the Security role. Administrators in this group are responsible for ensuring all Junior Helpdesk administrators are added to the Junior Helpdesk group. 242

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322
  • 323
  • 324
  • 325
  • 326
  • 327
  • 328
  • 329
  • 330
  • 331
  • 332
  • 333
  • 334
  • 335
  • 336
  • 337
  • 338
  • 339
  • 340
  • 341
  • 342
  • 343
  • 344
  • 345
  • 346
  • 347
  • 348
  • 349
  • 350
  • 351
  • 352
  • 353
  • 354
  • 355
  • 356
  • 357
  • 358
  • 359
  • 360
  • 361
  • 362
  • 363
  • 364
  • 365
  • 366
  • 367
  • 368
  • 369
  • 370
  • 371
  • 372
  • 373
  • 374
  • 375
  • 376
  • 377
  • 378
  • 379
  • 380
  • 381
  • 382
  • 383
  • 384
  • 385
  • 386
  • 387
  • 388
  • 389
  • 390
  • 391
  • 392
  • 393
  • 394
  • 395
  • 396
  • 397
  • 398
  • 399
  • 400
  • 401
  • 402
  • 403
  • 404
  • 405
  • 406
  • 407
  • 408
  • 409
  • 410
  • 411
  • 412
  • 413
  • 414
  • 415
  • 416
  • 417
  • 418
  • 419
  • 420

Managing groups and user accounts
25
Managing groups
You can reduce the time that you spend managing user accounts by creating groups of similar user accounts and
assigning shared properties, such as software configurations or IT policies, to the group. Properties that you assign
to a group are assigned to all user accounts in the group.
You can assign properties to user accounts and administrator accounts at the individual level, group level, or domain
level. The BlackBerry® Administration Service applies properties to user accounts and administrator accounts using
the following hierarchy:
The properties at the individual level override the properties at the group level.
The properties at the group level override the properties at the domain level.
After you add a user account or administrator account to a group, you can override the properties that you configured
for the account at the group level or domain level by changing the properties at the user account level.
If you remove a user account or administrator account from a group, the account name remains in the global users
list but it does not appear in the group list.
You can either create user-specific groups and assign roles to those groups or use the default user groups that contain
pre-existing roles.
If you are managing a large number of groups (over 3000) using the BlackBerry Administration Service in a single
domain, your organization's environment might experience a performance impact.
Using default groups to manage user accounts and administrator accounts
The BlackBerry® Enterprise Server installation includes default groups that have preconfigured administrative roles.
You can use the default groups in your organization's environment instead of creating specific administrative groups.
Each default group consists of a set of preconfigured rules which specify the information that administrators can
view and the tasks that they can perform using the BlackBerry Administration Service and BlackBerry Monitoring
Service.
The default groups ensure users without administrative privileges cannot escalate their permissions, for example,
junior administrators cannot escalate their roles to senior administrator roles.
Default group
Description of the default group
Administrators
This is a preconfigured group for BlackBerry Administration Service
administrators. This groups has the permissions assigned to the Security
role.
Administrators in this group are responsible for ensuring all Junior Helpdesk
administrators are added to the Junior Helpdesk group.
Administration Guide
Managing groups and user accounts
242