Why should I use DRA Assistant Admin groups to delegate my security model? (NETIQKB52783)

  • 7752783
  • 02-Feb-2007
  • 15-Nov-2011

Environment

Directory & Resource Administrator 7.x
Directory & Resource Administrator 8.x

Situation

Is there any benefit to assigning roles and ActiveViews to DRA Assistant Admin groups versus directly using native Active Directory (AD) groups?

Can I delegate my security model in DRA using Windows AD groups instead of using DRA Assistant Admin groups?

Why should I use DRA Assistant Admin groups to delegate my security model?

Resolution

You could delegate your security model by directly using Windows AD groups. However, we recommend you use DRA Assistant Admin groups for the following reasons:

  • If you use Windows AD groups and users directly to delegate your security model, then every time you add someone to an ActiveView you would need to force a Multi Master replication for all the DRA servers to see the changes.
  • Using DRA Assistant Admin groups to delegate your security model in DRA makes troubleshooting ActiveView issues much easier from a support standpoint.

We recommend you add Windows AD groups into your DRA Assistant Admin groups. Then when you want to add someone into an ActiveView, you can add them to the Windows AD group included in the DRA Assistant Admin group associated with the ActiveView.

Additional Information

Formerly known as NETIQKB52783