10.1 Built-in Roles

Built-in assistant administrator roles provide immediate access to a set of commonly used powers. You can extend your current security configuration by using these default roles to delegate power to specific user accounts or other groups.

These roles contain the powers required to perform common administration tasks. For example, the DRA Administration role contains all the powers required to manage objects. To use these powers, however, the role must be associated with a user account or an assistant administrator group and the managed ActiveView.

Because built-in roles are part of the default delegation model, you can use the built-in roles to quickly delegate power and implement security These built-in roles address common tasks you can perform through the DRA user interfaces. The following list describes each built-in role and summarizes the powers associated with that role.

Application Servers Administration

Provides the powers required to configure, view, and delete application server configurations.

Audit All Objects

Provides all the powers required to view properties of objects, policies, and configurations across your enterprise. This role does not allow an assistant administrator to modify properties. Assign this role to assistant administrators responsible for auditing actions across your enterprise. Allows assistant administrators to view all nodes except the Custom Tools node.

Audit Limited Account and Resource Properties

Provides powers for all object properties.

Audit Resources

Provides all the powers required to view properties of managed resources. Assign this role to assistant administrators responsible for auditing resource objects.

Audit Users and Groups

Provides all the powers needed to view user account and group properties, but no powers to modify these properties. Assign this role to assistant administrators responsible for auditing account properties.

Azure Group Administration

Provides all the powers required to manage azure groups and azure membership.

Azure User Administration

Provides all the powers required to create, modify, delete, enable, disable, and view properties of manage azure user. Assign this role to assistant administrators responsible for managing azure user.

Built-in Scheduler - Internal Use Only

Provides powers to schedule when DRA refreshes the cache.

Clone User with Mailbox

Provides all the powers required to clone an existing user account along with the account mailbox. Assign this role to assistant administrators responsible for managing user accounts.

NOTE:To allow the assistant administrator to add the new user account to a group during the clone task, also assign the Manage Group Memberships role.

Computer Administration

Provides all the powers required to modify computer properties. This role allows assistant administrators to add, delete, and shut down computers, as well as synchronize domain controllers. Assign this role to assistant administrators responsible for managing computers in the ActiveView.

Configure Servers and Domains

Provides all the powers required to modify Administration server options and managed domains. Also provides powers necessary to configure and manage Azure tenants. Assign this role to assistant administrators responsible for monitoring and maintaining the Administration servers and managing Azure tenants.

Contact Administration

Provides all the powers required to create a new contact, modify contact properties, or delete a contact. Assign this role to assistant administrators responsible for managing contacts.

Create and Delete Computer Accounts

Provides all the powers required to create and delete a computer account. Assign this role to assistant administrators responsible for managing computers.

Create and Delete Groups

Provides all the powers required to create and delete a group. Assign this role to assistant administrators responsible for managing groups.

Create and Delete Resource Mailbox

Provides all the powers required to create and delete a a mailbox. Assign this role to assistant administrators responsible for managing mailboxes.

Create and Delete Resources

Provides all the powers required to create and delete shares and computer accounts, and clear event logs. Assign this role to assistant administrators responsible for managing resource objects and event logs.

Create and Delete User Accounts

Provides all the powers required to create and delete a user account. Assign this role to assistant administrators responsible for managing user accounts.

DRA Administration

Provides all powers to an assistant administrator. This role gives a user the permissions to perform all administration tasks within DRA. This role is equivalent to the permissions of an administrator. An assistant administrator associated with the DRA Administration role can access all Directory and Resource Administrator nodes.

Dynamic Group Administration

Provides all the powers required to manage Active Directory dynamic groups.

Execute Advanced Queries

Provides all the powers required to execute saved advanced queries. Assign this role to assistant administrators responsible for executing advanced queries.

Group Administration

Provides all the powers required to manage groups and group memberships, and view corresponding user properties. Assign this role to assistant administrators responsible for managing groups or account and resource objects that are managed through groups.

Help Desk Administration

Provides all the powers required to view user account properties, and to change passwords and password related properties. This role also allows assistant administrators to disable, enable, and unlock user accounts. Assign this role to assistant administrators responsible for Help Desk duties associated with ensuring users have proper access to their accounts.

Mailbox Administration

Provides all the powers required to manage Microsoft Exchange mailbox properties. If you use Microsoft Exchange, assign this role to assistant administrators responsible for managing Microsoft Exchange mailboxes.

Manage Active Directory Collectors, DRA Collectors, and Management Reporting Collectors

Provides all the powers required to manage Active Directory Collectors, DRA Collectors, and Management Reporting Collectors for data collection. Assign this role to assistant administrators responsible for managing reporting configuration.

Manage Active Directory Collectors, DRA Collectors, Management Reporting Collectors, and Database Configuration

Provides all the powers required to manage Active Directory Collectors, DRA Collectors, Management Reporting Collectors, and database configuration for data collection. Assign this role to assistant administrators responsible for managing reporting and database configuration.

Manage Advanced Queries

Provides all the powers required to create, manage, and execute advanced queries. Assign this role to assistant administrators responsible for managing advanced queries.

Manage and Execute Custom Tools

Provides all the powers required to create, manage, and execute custom tools. Assign this role to assistant administrators responsible for managing custom tools.

Manage Clone Exceptions

Provides all the powers required to create and manage clone exceptions.

Manage Computer Properties

Provides all the powers required to manage all properties for a computer account. Assign this role to assistant administrators responsible for managing computers.

Manage Database Configuration

Provides all the powers required to manage database configuration for Management reports. Assign this role to assistant administrators responsible for managing reporting database configuration.

Manage Dynamic Distribution Groups

Provides all the powers required to manage Microsoft Exchange dynamic distribution groups.

Manage Exchange Mailbox Rights

Provides all the powers required to manage security and rights for Microsoft Exchange mailboxes. If you use Microsoft Exchange, assign this role to assistant administrators responsible for managing Microsoft Exchange mailbox permissions.

Manage Group Email

Provides all the powers required to view, enable, or disable the email address for a group. Assign this role to assistant administrators responsible for managing groups or email addresses for account objects.

Manage Group Membership Security

Provides all the powers required to designate who can view and modify Microsoft Windows group memberships through Microsoft Outlook

Manage Group Memberships

Provides all the powers required to add and remove user accounts or groups from an existing group, and view the primary group of a user or computer account. Assign this role to assistant administrators responsible for managing groups or user accounts.

Manage Group Properties

Provides all the powers required to manage all properties for a group. Assign this role to assistant administrators responsible for managing groups.

Manage Mailbox Move Requests

Provides all the powers required to manage mailbox move requests.

Manage Policies and Automation Triggers

Provides all the powers required to define policies and automation triggers. Assign this role to assistant administrators responsible for maintaining company policies and automating workflows.

Manage Printers and Print Jobs

Provides all the powers required to manage printers, print queues, and print jobs. To manage print jobs associated with a user account, the print job and the user account must be included in the same ActiveView. Assign this role to assistant administrators responsible for maintaining printers and managing print jobs.

Manage Resource Mailbox Properties

Provides all the powers required to manage all properties for a mailbox. Assign this role to assistant administrators responsible for managing mailboxes.

Manage Resources for Managed Users

Provides all the powers required to manage resources associated with specific user accounts. The assistant administrator and the user accounts must be included in the same ActiveView. Assign this role to assistant administrators responsible for managing resource objects.

Manage Security Model

Provides all the powers required to define the Administration rules, including ActiveViews, assistant administrators, and roles. Assign this role to assistant administrators responsible for implementing and maintaining your security model.

Manage Services

Provides all the powers required to manage services. Assign this role to assistant administrators responsible for managing services.

Manage Shared Folders

Provides all the powers required to manage shared folders. Assign this role to assistant administrators responsible for managing shared folders.

Manage Temporary Group Assignments

Provides all the powers required to create and manage temporary group assignments. Assign this role to assistant administrators responsible for managing groups.

Manage UI Reporting

Provides all the powers required to generate and export Activity Detail reports for users, groups, contacts, computers, organizational units, powers, roles, ActiveViews, containers, published printers, and assistant administrators. Assign this role to assistant administrators responsible for generating reports.

Manage User Dial in Properties

Provides all the powers required to modify the dial in properties of user accounts. Assign this role to assistant administrators responsible for managing user accounts that have remote access to the enterprise.

Manage User Email

Provides all the powers required to view, enable, or disable the email address for a user account. Assign this role to assistant administrators responsible for managing user accounts or email addresses for account objects.

Manage User Password and Unlock Account

Provides all the powers required to reset the password, specify password settings, and unlock a user account. Assign this role to assistant administrators responsible for maintaining user account access.

Manage User Properties

Provides all the powers required to manage all properties for a user account, including Microsoft Exchange mailbox properties. Assign this role to assistant administrators responsible for managing user accounts.

Manage Virtual Attributes

Provides all the powers required to create and manage virtual attributes. Assign this role to assistant administrators responsible for managing virtual attributes.

Manage WTS Environment Properties

Provides all the powers required to change the WTS environment properties for a user account. Assign this role to assistant administrators responsible for maintaining the WTS environment or managing user accounts.

Manage WTS Remote Control Properties

Provides all the powers required to change the WTS remote control properties for a user account. Assign this role to assistant administrators responsible for maintaining WTS access or managing user accounts.

Manage WTS Session Properties

Provides all the powers required to change the WTS session properties for a user account. Assign this role to assistant administrators responsible for maintaining WTS sessions or managing user accounts.

Manage WTS Terminal Properties

Provides all the powers required to change the WTS terminal properties for a user account. Assign this role to assistant administrators responsible for maintaining WTS terminal properties or managing user accounts.

OU Administration

Provides all the powers required to manage organizational units. Assign this role to assistant administrators responsible for managing the Active Directory structure.

Public Folder Administration

Provides the powers to create, modify, delete, enable or disable mail and view the properties of your Public Folder. You can assign this role to all assistant administrators who are responsible for managing Public Folder.

Rename Group and Modify Description

Provides all the powers required to modify the name and description of a group. Assign this role to assistant administrators responsible for managing groups.

Rename User and Modify Description

Provides all the powers required to modify the name and description of a user account. Assign this role to assistant administrators responsible for managing user accounts.

Replicate Files

Provides all the powers required to upload, delete and modify file information. Assign this role to assistant administrators responsible for replicating files from the primary Administration server to other Administration servers in the MMS and the DRA client computers.

Reset Local Administrator Password

Provides all the powers to reset the local administrator account password and view the name of the computer administrator. Assign this role to assistant administrators responsible for managing the administrator accounts.

Reset Password

Provides all the powers required to reset and modify passwords. Assign this role to assistant administrators responsible for password management.

Reset Password and Unlock Account Using SPA

Provides all the powers required to use Secure Password Administrator to reset passwords and unlock user accounts.

Reset Unified Messaging PIN Properties

Provides all the powers required to reset Unified Messaging PIN properties for user accounts.

Resource Administration

Provides all the powers required to modify properties of managed resources, including resources associated with any user account. Assign this role to assistant administrators responsible for managing resource objects.

Resource Mailbox Administration

Provides all the powers required to manage resource mailboxes.

Self Administration

Provides all the powers required to modify basic properties, such as telephone numbers, of your own user account. Assign this role to assistant administrators to allow them to manage their own personal information.

Shared Mailbox Administration

Provides all the powers required to create, modify, delete and view the properties of your shared mailboxes. Assign this role to all assistant administrators responsible for managing shared mailboxes.

Start and Stop Resources

Provides all the powers required to pause, start, resume, or stop a service, start or stop a device or printer, shut down a computer, or synchronize your domain controllers. Also provides all the powers required to pause, resume, and start services, stop devices or print queues, and shut down computers. Assign this role to assistant administrators responsible for managing resource objects.

Transform a User

Provides all the powers required to add a user to or remove a user from groups found in a template account, including the ability to modify the user's properties while transforming the user.

Unified Change History Server Administration

Provides the powers required to configure, view, and delete Unified Change History server configurations.

User Administration

Provides all the powers required to manage user accounts, associated Microsoft Exchange mailboxes, and group memberships. Assign this role to assistant administrators responsible for managing user accounts.

View Active Directory Collectors, DRA Collectors, Management Reporting Collectors, and Database Configuration Information

Provides all the powers required to view AD collectors, DRA collectors, management reporting collectors, and database configuration information.

View All Computer Properties

Provides all the powers required to view properties of a computer account. Assign this role to assistant administrators responsible for auditing computers.

View All Group Properties

Provides all the powers required to view properties for a group. Assign this role to assistant administrators responsible for auditing groups.

View All Resource Mailbox Properties

Provides all the powers required to view properties for a resource mailbox. Assign this role to assistant administrators responsible for auditing resource mailboxes.

View All User Properties

Provides all the powers required to view properties for a user account. Assign this role to assistant administrators responsible for auditing user accounts.

Workflow Automation Server Administration

Provides the powers required to configure, view, and delete Workflow Automation server configurations.

WTS Administration

Provides all the powers required to manage Windows Terminal Server (WTS) properties for user accounts in the ActiveView. If you use WTS, assign this role to assistant administrators responsible for maintaining the WTS properties of user accounts.

10.1.1 Accessing Built-in Roles

Access built-in roles to audit the default delegation model or manage your own security settings.

To access built-in roles:

  1. Navigate to Delegation Management > Manage Roles.

  2. Ensure the search field is blank, and click Find Now in the List items that match my criteria pane.

  3. Select the appropriate role.

10.1.2 Using Built-in Roles

You cannot delete or modify built-in roles. However, you can incorporate the built-in roles into your existing delegation model or use these roles to design and implement your own model.

You can use built-in roles in the following ways:

  • Associate a built-in role with a user account or assistant administrator group. This association provides the user or assistant administrator group members with the appropriate powers for the task.

  • Clone a built-in role and use that clone as the basis for a custom role. You can add other roles or powers to this new role and remove powers originally included in the built-in role.

For more information about designing a dynamic delegation model, see Understanding the Dynamic Delegation Model.