Solved

Dynamic group memberships

Posted on 2004-04-23
3
254 Views
Last Modified: 2010-04-19
I know Aelita makes a tool that allows for dynamic group membership.

Is there any others out there? or can it be scripted somehow?

What I want is the ability to have an ACL group that will give rights to a folder based on an attribute in their user account (such as location field). I want it to be dynamic, so that if I change the attribute it will remove them from the group and add them to the appropriate group.

Anyone?

0
Comment
Question by:TheCleaner
  • 2
3 Comments
 
LVL 10

Accepted Solution

by:
KingHollis earned 250 total points
ID: 10904204
TheCleaner,

Using ADSI scripting, you can do such a thing:
1. You would have to create the groups and give the groups the access you require.
2. You would have to write the ADSI script(s) that would run against members in the group(s) looking for the attribute. If the attribute was not present in the member then you would have your batch file make a call to another ADSI script to remove the member.
3. You would also have to create another ADSI script which would run against all members in your domain looking for the attribute. If found, your batch file would make another call to another ADSI script(s) to add the members to specific groups.
4. Then you would either manually run these batch files or schedule them with the proper authority.

Sounds complicated, but it isn't really. It's just teduious and time consuming and will require you to become a bit familiar with ADSI scripting-- which you should because there are a lot of cool things admins can do without having to know a whole lot about programming. Otherwise, this is why Aelita gets paid the big bucks!
0
 
LVL 23

Author Comment

by:TheCleaner
ID: 11059280
KingHollis,

Thanks for the information.  We decided the Aelita product was well worth it in the long run, so that's the direction we went.

Thanks for your help though...points awarded, and a B grade given...
0
 
LVL 10

Expert Comment

by:KingHollis
ID: 11062511
TheCleaner,

Aelita makes good stuff, so definitely not a bad move.
Thanks for your consideration and best of luck!
0

Featured Post

Enabling OSINT in Activity Based Intelligence

Activity based intelligence (ABI) requires access to all available sources of data. Recorded Future allows analysts to observe structured data on the open, deep, and dark web.

Join & Write a Comment

The HP utility "HP Lights-Out Online Configuration Utility for Windows Server 2003/2008" could be of great use when it comes to remotely configure a HP servers ILO WITHOUT rebooting the server. We would only need to create and run scripts using thi…
Recently, I had the need to build a standalone system to run a point-of-sale system. I’m running this on a low-voltage Atom processor, so I wanted a light-weight operating system, but still needed Windows. I chose to use Microsoft Windows Server 200…
Sending a Secure fax is easy with eFax Corporate (http://www.enterprise.efax.com). First, Just open a new email message.  In the To field, type your recipient's fax number @efaxsend.com. You can even send a secure international fax — just include t…
Illustrator's Shape Builder tool will let you combine shapes visually and interactively. This video shows the Mac version, but the tool works the same way in Windows. To follow along with this video, you can draw your own shapes or download the file…

706 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

18 Experts available now in Live!

Get 1:1 Help Now