11.3 Extending Powers

You can add permissions or functionality to a power by extending that power.

For example, to allow an assistant administrator to create a user account, you can assign either the Create User and Modify All Properties power or the Create User and Modify Limited Properties power. If you also assign the Add New User to Group power, the assistant administrator can add this new user account to a group while using the Create User wizard. In this case, the Add New User to Group power provides an additional wizard feature. The Add New User to Group power is the extension power.

Extension powers cannot add permissions or functionality by themselves. To successfully delegate a task that includes an extension power, you must assign the extension power along with the power you want to extend.

NOTE:

  • To successfully create a group and include the new group in an ActiveView, you must have the Add New Group to ActiveView power in the specified ActiveView. The specified ActiveView must also include the OU or built-in container that will contain the new group.

  • To successfully clone a group and include the new group in an ActiveView, you must have the Add Cloned Group to ActiveView power in the specified ActiveView. The specified ActiveView must also include the source group as well as the OU or built-in container that will contain the new group.

The following table lists some examples of actions that are configurable when creating a new power or modifying the properties of an existing power:

To Delegate This Task

Assign This Power

And This Extension Power

Clone a group and include the new group in a specified ActiveView

Clone Group and Modify All Properties

Add Cloned Group to ActiveView

Create a group and include the new group in a specified ActiveView

Create Group and Modify All Properties

Add New Group to ActiveView

Create a mail enabled contact

Create Contact and Modify All Properties

Create Contact and Modify Limited Properties

Enable Email for New Contact

Create a mail enabled group

Create Group and Modify All Properties

Enable Email for New Group

Create a mail enabled user account

Create User and Modify All Properties

Create User and Modify Limited Properties

Enable Email for New User

Create a user account and add the new account to specific groups

Create User and Modify All Properties

Create User and Modify Limited Properties

Add New User to Group