Modifying groups in standard zones

In a standard zone, modifying a group profile in a zone requires the following permissions:

Select this target object To apply these permissions

The serviceConnectionPoint object for the group account

For example, if the UNIX group name is web-qa in the HKLab zone:


then select

serviceConnectionPoint objects

Click the Properties tab and select Allow to apply the following properties to this object only:

  • Read allowedAttributesEffective
  • Read objectGUID
  • Read Name

If you are changing the UNIX group name for a group, you need the following additional permissions applied to this object:

  • Read name
  • Write name
  • Write Name

Note The Name property is the common name (cn) of the serviceConnectionPoint object.