Directory & Resource Administrator 8.x
Can I delegate my security model in DRA using Windows AD groups instead of using DRA Assistant Admin groups?
Why should I use DRA Assistant Admin groups to delegate my security model?
You could delegate your security model by directly using Windows AD groups. However, we recommend you use DRA Assistant Admin groups for the following reasons:
- If you use Windows AD groups and users directly to delegate your security model, then every time you add someone to an ActiveView you would need to force a Multi Master replication for all the DRA servers to see the changes.
- Using DRA Assistant Admin groups to delegate your security model in DRA makes troubleshooting ActiveView issues much easier from a support standpoint.
We recommend you add Windows AD groups into your DRA Assistant Admin groups. Then when you want to add someone into an ActiveView, you can add them to the Windows AD group included in the DRA Assistant Admin group associated with the ActiveView.