Video Screencast Help
Symantec to Separate Into Two Focused, Industry-Leading Technology Companies. Learn more.

Question: How to Delegate custom Roles to User support staff?

Created: 03 Oct 2012 • Updated: 07 Oct 2012 | 4 comments
This issue has been solved. See solution.

Hello Symantec gurus,

I have recently installed SMP 7.2 SP2. I have added my user support staff into a new role. I would like to assign permission to have them install Agents, push patches, Manage computers and software, create jobs-tasks-policies, remote control. Mostly delegate user support staff all the required permission to perform the tasks without giving them extra permission on the SMP server. I have used the built-in roles like level 1 & 2 workers, patch management rollout however they get more than the required permissions. There are above 100 permission with combination of the roles and I’m not sure what is needed. Is there any article or link that explains how to delegate the role to helpdesk staff?  

Much appreciated for your help.

Asad

Comments 4 CommentsJump to latest comment

Qatar525's picture

Update: I manage to assign console permission using the security role manager. The user support staff can see all the menus but do not have the permission to access them. Where do i give them the permission to run ? for example to access "push symantec management agents"

Qatar525's picture

What is the difference between inherited and non-inherited permission. this makes it more complicated. SMP documentation does not say much about it.

Zac H's picture

The best advice I think I ever read was from Thomas Baird (sp?).  That advice was to clone the Symantec Administrators role for ANY custom roles.  It's still buggy, so there are still things not exposed in the UI.  So its a good idea to use the admins role and pare it down.

Inherited means the permission came from something above it.  Non-inherited is something applied at that level.

Role and scope is an art, man.  Good luck.

SOLUTION