Configure automatic list rights management

<< Inhaltsverzeichnis anzeigen >>

Navigation:  Start > Install & Config > Change configuration > File server (FS) change configuration > Add FS-specific change configurations >

Configure automatic list rights management

8.0 EN configuring automatic list rights management 01

 

The list right configuration includes several options for determining how 8MAN automatically ensures that users can navigate to the folders that they have access to.

Compared to Microsoft native tools you can avoid many cumbersome and error prone administrative steps.




8.0 EN configuring automatic list rights management 02

 

Activate the automatic list rights management option.




8.0 EN configuring automatic list rights management 03

 

Use the slider to determine the level of folder depth that 8MAN manages.

Level 0

Level 0 is the shared folder (share level). This folder is visible to users based on share rights. An assignment of list rights on this level is not required.

green levels

8MAN creates list groups for every level. The access rights groups become members of list groups.

blue levels

8MAN does not create list groups for these levels. Access groups are provisioned by entering list rights directly into the  Access Control List (ACL). This way overall less groups are created and Kerberos token size is minimized. On the other hand more ACL entries are required which may cause performance issues.

8.0 EN configuring automatic list rights management 04

 

Move the orange slider to exclude folder levels from the automatic creation of list groups. This is useful if users already have list rights to these folder levels.




8.0 EN configuring automatic list rights management 05

 

Activate this option to prevent access rights changes below the lowest "list-rights-level" plus one (for example level 6, as in the screenshot).

You should activate this option to prevent users from gaining access to levels that they are not able to navigate to.




8.0 EN configuring automatic list rights management 06

 

Select a list group mode.

This setting has no influence on Kerberos token size.




8.0 EN configuring automatic list rights management 07

 

This option allows you to prevent permission changes to specific folder levels (keep it as parent for inheritance).

It is more beneficial to protect folder levels by assigning "restricted modify", as these require fewer group memberships.