Accumulating Privileges Using Extended Schema - Dell iDRAC6 User Manual

Remote access controller 6
Hide thumbs Also See for iDRAC6:
Table of Contents

Advertisement

Users, user groups, or nested user groups from any domain can be added into
the Association Object. Extended Schema solutions support any user group
type and any user group nesting across multiple domains allowed by
Microsoft Active Directory.

Accumulating Privileges Using Extended Schema

The Extended Schema Authentication mechanism supports Privilege
Accumulation from different privilege objects associated with the same user
through different Association Objects. In other words, Extended Schema
Authentication accumulates privileges to allow the user the super set of all
assigned privileges corresponding to the different privilege objects associated
with the same user.
Figure 6-2 provides an example of accumulating privileges using Extended
Schema.
Figure 6-2. Privilege Accumulation for a User
Domain 1
Domain 2
A01
A02
Group1
Priv1
Priv2
User1
User2
iDRAC1
iDRAC2
The figure shows two Association Objects—A01 and A02. User1 is associated
to iDRAC2 through both association objects. Therefore, User1 has
accumulated privileges that are the result of combining the privileges set for
objects Priv1 and Priv2 on iDRAC2.
126
Using iDRAC6 With Microsoft Active Directory

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents