Video Screencast Help
Search Video Help Close Back
to help
New in the Rewards Catalog: Vouchers for "Symantec Technical Specialist" and "Symantec Certified Specialist" exams.

Eliminate SEPM admin accounts: Use AD Security Group membership & SSO

Created: 24 Nov 2009 | 1 comment
JRV's picture
2 Agree
1 Disagree
+1 3 Votes
Login to vote

At present, SEPM's AD integration for admin accounts is to create SEPM admins with names matching AD usernames. All that saves us is having to set the passwords. Nice, but not enough.

I want to be able to create AD Security Groups for each SEPM role, such as "SEP System Administrators", "SEP Limtied Administrators", "SEP Report-Only Administrators", etc., and then assign AD user accounts to these groups. In SEPM, I'd assign various admin roles to these Groups. Then, when a user logs on to SEPM, SEPM would query AD for the Group membership to determine if access is allowed, and the level of access. I use other configurators like this; no reason SEPM couldn't do it, too.

Furthermore, a user shouldn't have to log on to SEPM at all. SEPM should use the credentials of the logged-on user (or Run As).

Comments

matt will fix it's picture
10
Jan
2010
0 Votes 0
Login to vote

What if you're not using

What if you're not using Active Directory? Or multiple domains?