Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

The Austin Active Directory Department Group Tools are used to manage a Department's groups using a convenient and easy to use web interface.  They allow for group management in scenarios where the native Active Directory tools are not installed or where they cannot even be installed such as on a computer running a non-Windows OS.


All groups created in the Department Group Tools reside under austin.utexas.edu/Groups/Managed (not the Department OU under austin.utexas.edu/Departments.

Because of this, Department OU Administrators do not have the ability to update group memberships of these groups.


Groups that were created in a Department OU can still be managed using the Department Group Tools.


Roles

The following roles are defined in the Department Group Tools:

RolesGroup ScopeAvailable ActionsHow Someone Falls into Scope of the Role

Status
subtletrue
colourBlue
titleOU Owner

Groups native to the Department Group Tools

Add Department Group Administrator

Remove Department Group Administrator

When a Department OU is created, the requestor provides a list of the initial OU Owners.

Department OU Owners can edit (add/remove) owners of the Department OU.

If a Department falls in the scenario where there are no valid OU Owners (for example, all of the owners are former staff), the owners can be updated by one of the following processes:

  • The Head of the Department submits a request to the AD team, specifying the EIDs of the new OU Owners.
  • IT staff member from the department contacts the ISO who will review it and then submit a request to the AD team, specifying the EIDs of the new OU Owners.

Status
subtletrue
colourGreen
titleGroup Administrator

Create Group

Delete Group

Rename Group

Update Group Description

Set Group Managers

Department OU Owners manage the Group Admins.

Status
subtletrue
colourYellow
titleGroup Manager

Add a Group Member

Remove a Group Member

A groups's manager is set by a Department Group Administrator.

Status
subtletrue
titleGroup Manager

Groups existing within a Department OU

Add a Group Member

Remove a Group Member

You (or a group you are a member of) is set on the ManagedBy of a group.

Group Location in AD

...

A Department OU Administrator sets the Managed By on a group located within a Department OU.



Add Department Group Administrator

Status
subtletrue
colourBlue
titleOU Owner

...

Remove Department Group Administrator

Status
subtletrue
colourBlue
titleOU Owner


Create Group

Status
subtletrue
colourGreen
titleGroup Administrator


Delete Group

Status
subtletrue
colourGreen
titleGroup Administrator


Rename Group

Status
subtletrue
colourGreen
titleGroup Administrator


Update Group Description

Status
subtletrue
colourGreen
titleGroup Administrator


Set Group Managers

Status
subtletrue
colourGreen
titleGroup Administrator


Add a Group Member

Status
subtletrue
colourYellow
titleGroup Manager

...

Remove a Group Member

Status
subtletrue
titleGroup Manager

Logging

All actions taken in the Department Group Tools is logged and sent to Splunk.

Moving a Group from a Department OU to Managed Groups

A department (Owner | Administrator | either?) can request the movement of a group from their Department OU to the corresponding Managed Groups OU.

...

...

Group

...

Manager

...