Symantec Management Platform (Notification Server)

 View Only

Problems with delegating security on SEP migration jobs in Altiris 7.1

  • 1.  Problems with delegating security on SEP migration jobs in Altiris 7.1

    Posted Mar 26, 2013 05:43 PM

    Hi,

    I have recently created SEP migration jobs, in the Altiris console,  to push out our SEP clients to our workstatoins via this process.

    http://www.symantec.com/business/support/index?page=content&id=HOWTO60858&actp=search&viewlocale=en_US&searchid=1364328647099

    The jobs were created fine and seem to work fine when I schedule them. I am setup as a Symantec Admin in the console.  However, I am trying to setup access for my PC Techs to be able to schedule them.  I have a security role in place that allows the techs to push various other jobs already (Office, Adobe reader, etc...).  I have modified this role (for the pc techs) to include the migration jobs with the "Run Task" permission, just like any other job.  After modifying the roles, the techs can see the jobs like normal, but whenever they try and schedule the migration jobs they get the following error, basically stating they don't have permissions to certain tasks within the migration job.  I have created new roles, cloned roles, nothing works unless they are part of the symantec administrators role. Unfortunatley adding all my techs to the admin role is not going to work as a solution. 

    perm_error.jpg

     

    Unlike other jobs I have created (office, adobe, java...), these migration jobs were created from some kind of internal wizard when running through the process from the link above. As such, the individual "steps" or tasks within this job are hidden, or at least appear to be when looking at the job. I suspect the permission error is a result of my techs, or role that the techs are in, do not have the proper permissions on these sub tasks.   I can see the individual job tasks, when i drill down into the history details of a computer, that I was able to schedule the job on, as an admin.  It looks like this:

    sep.JPG

    I have looked everywhere hi and low for these tasks/steps within the console, so i can set perms on them,  and i cannot find them anywhere except in the history after the migration job has been scheduled.  I have opened a ticket with symantec support.  I have been working with a tech for about a week now. Progress has been pretty slow because I dont really think he understands completely what is going on here, even though I have tried to explain.  There is a bit of a language barrier and every time he calls he says hes going to speak with "backline" and call me back.  Is this a bug? Am I missing something?  I feel like setting permissions on something like this should be simpler than they are. Any help would be appreciated.  Thanks