Managing role assignments in a zone

To manage role assignments in a zone, your user account must be set with the following permissions:

Select this target object To apply these permissions

Container for the authorization store

For example:

domain/UNIX/Zones/arcade/Authorization

On the Object tab, select Allow to apply the following properties to this object only:

  • List contents
  • Read all properties
  • Create all child objects
  • Delete all child objects

Click the Properties tab and select Allow to apply the following properties to this object only:

  • Write msDS-AzApplicationData

Click the Properties tab and select Allow to apply the following properties to msDS-AzRole objects:

  • Write displayName
  • Write msDS-AzApplicationData
  • Write msDS-TasksForAzRole
  • Write msDS-MembersForAzRole

Computers container in the zone

On the Object tab, select Allow to apply the following properties to this object only:

  • Create Container Right

This permission is required to allow a delegated user to make the first role assignment after a computer is joined to Active Directory.

AzRoleObjectContainer

On the Object tab, select Allow to apply the following properties to the msDS-AzApplication object and all child objects:

  • List contents
  • Read all properties
  • Create msDS-AzRole objects
  • Delete msDS-AzRole objects

Click the Properties tab and select Allow to apply the following properties to msDS-AzRole objects:

  • Write displayName
  • Write msDS-AzApplicationData
  • Write msDS-TasksForAzRole
  • Write msDS-MembersForAzRole

Click the Properties tab and select Allow to apply the following properties to msDS-AzAdminManager objects:

  • Write msDS-AzApplicationData
AzOpObjectContainer

On the Object tab, select Allow to apply the following properties to this object only:

  • Read all properties
  • Create msDS-AzOperation objects
  • Delete msDS-AzOperation objects
  • Create msDS-AzRole objects
  • Delete msDS-AzRole objects

Click the Properties tab and select Allow to apply the following properties to msDS-AzRole objects:

  • Write displayName
  • Write msDS-AzApplicationData
  • Write msDS-TasksForAzRole
  • Write msDS-MembersForAzRole

Click the Properties tab and select Allow to apply the following properties to msDS-AzOperation objects:

  • Read name
  • Read Name
  • Write msDS-AzApplicationData
  • Write name
  • Write description