Locking down users

I'm trying to find a way to give access to some IT staff in some of our smaller sites, but I'm not finding exactly what I'd like to do. Our hope is that we can give them access similar to the "Help desk user" preset (locks them down to only the message tracking screen). Unfortunately, we'd also like to restrict what domains they are able to track messages for, but I'm not able to find any way to restrict them other than the pre-made categories.
Anyone ever done anything like that before, or know if it's even possible?

Hello -
We do not have that ability available in Message Tracking. You might be able to work around this limitation by having certain admins / help desk users only have access to certain appliances (if you could limit each site's appliance to handle only certain domains). You might chose to only give these help desk users quarantine access for simple tasks, or perhaps delegate only the more savvy help desk folks with more access.
Take care!
Andrew Wurster

Similar Messages

  • Can we lock down user admin functionality to allow password changes only?

    Hi,
    Is it possible to lock down the user admin functionality so a specific role can only change passwords?
    We have a large user base of >10K infrequent users that are forced to change their passwords every 30 days. We suspect a lot will require password changes and we are keen to not have the tech team spending most of their time dealing with such requests. We would like to pass this task onto data management but not allow them the system administrator functionality.
    We know we can create a responsibility with a limited menu available so the operator can see only the security/user/define menu. But this will still allow the person to add responsibilities to existing user accounts and create new user accounts, both of which are deemed unacceptable security risks. Is it possible to lock down the form as well as the menu? Allowing operators to only change the password of existing users? Or can we use the custom.pll to error when a user tries to do anything except edit the password field when in this role?
    Thanks
    Matt

    You should be able to do that. You would create a new privilege level (ie 7), assign all commands to that level except (this is my guess) the command vpn-sessiondb, you would put that at a lower privilege level (ie 6). Here's a write-up that may help getting you in the right direction.
    http://www.packetpros.com/2012/08/read-only-asdm.html

  • Wireless Controller locking down User per SSID

    I am using Wireless Controller 4112. We use WPA enterprise mode for authentication and encryption via Microsoft IAS server and MS AD domain.
    My question is how to lock down a user to a specific SSID? I would guess that this is via some vendor specific radius attributes, am I right? And if so, what would be the name (and ID) for the attributes?
    Thanks in advance.

    Making progress in setting up the wireless controller with multiple VLAN and WLAN/SSID. I create a virtaul interface at the controller and assign a VLAN number to it. The controller mgmt port is also set to a trunk port. Create a new SSID WLAN and have it mapped to the new virtual interface. Things work good.
    The new problem I am trying to solve is how to prevent wired users to access the controller admin web interface via the virtual interface IP. I try create ACL and map it to the virtual interface. It doesn't seem working.

  • Pymt Terms - Ability to LOCK down Users from Input or Change

    Is there an easy  way to prevent Users from Entering or Changing Payment Terms on an Invoice? Note in other module areas there is an easy way to Define the Screen Layout for Optional/Required/Display etc.,  (Materials Managment / Purchasing) .   Thanks!!!

    Hi Santosh
    I have been off working on another area. Your feedback is always so helpful. As stated before, your suggestion allows me to Suppress Payment Term, but is there a way to simply Ghost (shows up but user cannot change it)...
    btw, I want to allow only specific Security Group/Authorizations to change the Payment Method in FB60 or any Logistics Invoice... Have you run across this?  I will be submitting a new thread on this but thought I would ask here as well...
    As always... Thank you!!!!

  • Access Connections v4.52 - user rights in locked down environment

    I'm currently working on a small project to deploy various Lenovo wireless drivers, Access Connections v4.52, Hotkey and Power Management drivers via SMS but have come across a slight issue with Access Connections that I can't seem to resolve.
    I'm hoping to provide my locked down users with a selection of standard profiles that are copied to their machines on logon but would also like to give them the ability to create and modify new ones too - this is where I'm having problems.
    Through Group Policy I have set:
    Allow Windows users without administrator privileges to create and apply WLAN location profiles using Find Wireless Network function
    HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Lenovo\AccessConnection\EnableCreateProfilewithFWN 1
    Allow Windows users without administrator privileges to create and apply location profiles
    HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Lenovo\AccessConnection\EnableUserMode 1
    I have also manually set the following:
    HKEY_LOCAL_MACHINE\SOFTWARE\Lenovo\Access Connections\Install\AllowPrfCreationThruFWN 1
    I couldn't find a key for the 'EnableUserMode' option
    Unfortunately, none of these give standard users access to create or modify profiles.
    Have any of you come across this in your environment and if so did you manage to come up with a suitable solution?
    Thanks in advance.

    Hi,
    the steps, that you performed are correct.
    However I would not do the last step:
    HKEY_LOCAL_MACHINE\SOFTWARE\Lenovo\Access Connections\Install\AllowPrfCreationThruFWN 1
    This might cause confusiong.
    I have just tested it in here and it's working fine with the 5.x version of AC
    Cheers

  • Locking down Firefox Connection settings

    Due to Google removing their support for IE8, I'm being forced down the road to look at an alternative Browser to support my users when connecting to Google tools.
    Using IE I have locked down users to enforce them to use our cloud based web security using a PAC file and now need to use the same with firefox.
    I've edited the registry with the PAC file but now want to effectivly grey out the options on the Connections setting page
    I've read a few guides and tried them but they are all for older version of FF.
    Can anyone out there point me in the right direction?

    If you really want to prevent users from changing settings then the only way to achieve this is via a mozilla.cfg file.
    It is not really that difficult.<br />
    You need to create to plain text files.
    Place a file local-settings.js in the defaults\pref folder where you also find the file channel-prefs.js to specify using mozilla.cfg.
    <pre><nowiki>pref("general.config.filename", "mozilla.cfg");
    pref("general.config.obscure_value", 0); // use this to disable the byte-shift
    </nowiki></pre>
    The mozilla.cfg file to be located in the main Firefox program folder should contain these lines:
    <pre><nowiki>// mzila.cfg should start with a comment line
    lockPref("network.proxy.type", 2);
    </nowiki></pre>
    See also:
    *http://kb.mozillazine.org/network.proxy.type
    *http://kb.mozillazine.org/Locking_preferences

  • How Creative Cloud working under locked down IT administration environment

    We are  existing CS6 and would like to sign for Creative Cloud. Just want to know how it works on the locked down user computers (without local administrator rights)?
    DISCLAIMER The contents of this email and any attachments (together "this email") may contain information that is confidential to Breville Group Limited (and/or its associated entities) (together"BRG"). Information contained in this email is subject to copyright. If you are not the intended recipient, you cannot print, use, rely, or disseminate any part of this email. If you receive this email in error, please notify us immediately by return e-mail and erase all copies. If you are the intended recipient of this email you should not copy, disclose, or distribute this email without the authority of BRG. Any views expressed in this email are those of the individual sender, except where the sender specifically states them to be the views of BRG. If this email contains any defamatory comments expressed by the individual sender, these comments are made outside the scope of his/her authority. BRG does not accept liability in respect of such defamatory comments. BRG does not warrant that the integrity of this email has been maintained, or that this email is free of errors or viruses, and has not been intercepted or interfered with. It is your responsibility to scan this email for computer viruses and other defects. BRG does not accept liability for any loss or damage however caused, whether by negligence or otherwise, which may result directly or indirectly from this email. In any event, BRG's liability is limited to the cost of re-supplying this email. Please consider the environment before printing this email. ***************************************************************

    The deployment is just the same like for the conventional suites and the same rules apply, so I'm not sure what you are asking.
    Mylenium

  • Locking down is it possible.

    Hello, We just installed a server 2012 r2 with the AD and Remote Desktop Services roles,  To host quickbooks.  All our client computers are running non professional versions of windows.  Can we use Group Policy to lock down user activities
    when logged into the remote desktop.  Users are logging in fine, but no group policy seems to be working.  I have been attempting to do this with no success and just want to make sure i am not wasting my time. 

    Hi,
    Thanks for posting in Windows Server Forum.
    As this thread has been quiet for a while, we assume that the issue has been resolved. At this time, we will mark it as ‘Answered’ as the previous steps should be helpful for many similar scenarios. If the issue still persists, please feel free to  reply
    this post directly so we will be notified to follow it up. 
    BTW,  we’d love to hear your feedback about the solution. By sharing your experience you can help other community members facing similar problems. 
    Thanks for your Support & understanding.
    Regards.
    Dharmesh Solanki
    TechNet Community Support

  • How do you modify the web.xml to lock down the pages from a user role

    how do you modify the web.xml to lock down the pages from a user role

    I'll make a stab at your question:
    The following is an example of where a URL is protected within a web.xml deployment descriptor. In this example, the URL /protectedA within the application is protected:
    <!-- security constraints -->
    <security-constraint>
    <web-resource-collection>
    <web-resource-name>protectedA</web-resource-name>
    <url-pattern>/protectedA</url-pattern>
    </web-resource-collection>
    <!-- authorization -->
    <auth-constraint>
    <role-name>sr_developer</role-name>
    </auth-constraint>
    </security-constraint>
    Sun's explaination here:
    http://java.sun.com/j2ee/1.4/docs/tutorial/doc/Security4.html

  • I have a Win7Pro SP1 PC locked down with a Group Policy as it is a public facing PC. PDF fillable forms cannot be completed when logged on as the restricted user. The forms work as a normal user. What are the user requirements/permissions needed to fill f

    I have a Win7Pro SP1 PC locked down with a Group Policy as it is a public facing PC. PDF fillable forms cannot be completed when logged on as the restricted user. The forms work as a normal user. What are the user requirements/permissions needed to fill forms?

    Well, try this (I was able to fix my with these steps):
    Go Utilities > Disk Utility
    Select your Startup Disk, e.g. Macintosh HD
    Then, under the First Aid Tab, click Verify Disk Permissions.
    If there are errors, then click repair Disk Permissions.
    After it is done, restart the computer and see if your problem is resolved.
    I hope this help.
    Zeke
    www.ZekeYuen.com/blog/

  • Locking down settings of an user account?

    Locking down settings of an user account?
    I have an IMac with 2 user accounts and a guest account.
    1 user account is the administrator account.
    The second user account is to be used by many people.
    How can I lock down settings for this account? Parental controls are insufisient, for instance: the settings for Safari can still be changed (default homepage etc)
    Also when connecting to the wireless network, the user is required to login with his own credentials, in this login window there is the username and password boxes and a "remember this login" checkbox, how can I set this checkbox as off by default? (and maybe grayed out so it can't be turned on).

    Hmmm, when a Guest logs out that info should be gone...
    ... the nice thing is that all traces of the person being there are erased after they log off. (At least that’s what Apple claims — there could be some caches left over if you look deep.)
    http://mac.tutsplus.com/tutorials/os-x/using-the-guest-account-in-os-x/

  • How do I lock down an iPad from having certain apps removed?

    Hello,
    We are a Microsoft-based enterprise that has purchased iPad 2 devices as a means of reducing costs of wireless services as well as integration with the 3G adapter (to reduce damage and theft). While I have had great success with the iPhone Configuration Utility and an MDM server, I need to ensure that users cannot remove the Find My iPad App which we use to track employees and ensure they do not lose or steal the device (since they can't remove the battery).
    What can I do to lock down this app from being removed and also, I want to give these employees access to load whatever they wish on these iPad units. We control their access through a VPN to a Microsoft Terminal Server and with Microsoft Exchange but I don't want iTunes and the CEO's credit card being used to purchase apps. Any ideas anyone? I know that this can be done and if not, it will be done by me.
    Brian Tate
    Information Technology Manager
    Grand Texas Homes Inc
    http://www.grandhomes.com

    I'm not sure about the apps, but to prevent theft, you'll also need to disable the power button and the ability to restore the ipad. You might also want to superglue in your Sim card because if they remove that, it wont be tracked unless they connect to WiFi.
    Also, I'm not so sure it is an app on the iPad. I think it is built into the mail, calendar and contacts options if you have a Mobile me account.  http://www.apple.com/ipad/find-my-ipad-setup/

  • Would like to know how to Completely Lock-down Windows 7 OS

    I don't have a general question..
    It's more like specifics about how to lock down windows 7 computers..
    Here's a little background information...
    I have two computers, both with win 7(Pro, and home prem).
    A family member can somehow bypass all bios and all windows security services... Everytime I go to work or school, he will power on my desktop and somehow 'hack' into the OS and install keyloggers or viruses so he can obtain my banking or other personal information.
    He also unlocks and deletes all the passwords so he can have access whenever he wants..
    Can someone please tell me how to do a complete lockdown? This is getting extremely annoying.. I've done everything that I can do; Also considering on switching my major to some sort of computer security. I'm starting to lose my mind over these months.. All
    help is appreciated.
    I've password protected BIOS
    I've disabled administrator accounts, i've put password on the admin and the guest user; locked the option to change passwords..
    All help is appreciated. Thank you all in advance.

    Hi,
    If you are using Windows 7 Professional, Ultimate, or Enterprise, you can use the Local Group Policy Editor to change policies that affect the security of your computer. Please check if the following policies meet you requirements.
    [User Configuration\Administrative Templates\Windows Components\Windows Explorer]
    Enable these two polices:
    Prevent access to drives from My Computer
    Hide these specified drives in My Computer
    For your reference:
    Lock Down PCs with Windows 7:
    http://technet.microsoft.com/en-us/windows/gg983426.aspx
    Also, restrict Which Programs a User Can Run. You can set rules in AppLocker in the Group Policy Editor that prevents all programs from being run.
    In addition, temporarily Lock Your Computer if Someone Tries to Guess Your Password
    If you share your computer with other family members or allow your friends to use it, you should have a password on your Windows account so no one else can log into it. However, someone may try to guess your password and log into your account. If this happens,
    you can temporarily lock your computer.
    You should also periodically change your password.
    If you suspect, you family member using a tool to bypass your password. You may use Malicious Software Removal Tool (http://www.microsoft.com/security/pc-security/malware-removal.aspx)
    to remove it.
    Hope it helps.
    Regards,
    Blair Deng
    Blair Deng
    TechNet Community Support

  • Directory preferences in a locked down PC environment

    How do I change:
    ide.pref.dir
    ide.pref.dir.base
    ide.user.dir
    ide.work.dir
    ide.work.dir.base
    user.home
    so that they don't reference a windows path like \\<server>\<user>$, but <drive letter>:\Oracle\sqldeveloper instead
    We use locked down PC's (with no access to the A: and C: drives) . And when we start SQLD we get 16 dialogue windows say that it cannot access the A: drive, to which we press the continue button. You also get the message when using the File navigator and the File->Open or File-Save functions.
    On upgrade from 1.5.1 to 1.5.4 the number of dialogue windows dropped from 16 to 2.
    We also always lose our connextions and have to reimport from a saved file every morning.
    A response to thread Connections fail to load at startup by user user641239 at 1-sep-2008 0:59 seems to have the solution - except it requires access to regedit. We don't have that. It's much too painful to get SQLD part of the PC build at the customer, so we need to be able to configure without resorting to regedit.
    Any help appreciated.
    Nic
    Edited by: Nic Atkin on 17-apr-2009 2:41
    Edited by: Nic Atkin on 17-apr-2009 2:54

    Hi FurryOne,
    There is a way to hide both A: and C: - but you need Windows Administrator rights to do it. Not possible in a locked down PC, So I'll live with it for now.
    I was also having the Configure File Type Associations at startup everytime problem (see
    Re: Configure File Type Associations at startup everytime
    So, my current solution looks like this:
    AddVMOption -Dide.pref.dir.base=M:\Oracle\
    AddVMOption -Dide.pref.dir=M:\Oracle\sqldeveloper
    AddVMOption -Dide.user.dir.base=M:\Oracle\
    AddVMOption -Dide.user.dir=M:\Oracle\sqldeveloper
    AddVMOption -Dide.work.dir.base=M:\Oracle\
    AddVMOption -Dide.work.dir=M:\Oracle\sqldeveloper
    AddVMOption -Duser.home=M:\
    AddVMOption -Dno.shell.integration=true

  • Locking down Win 8.1

    For security reasons, i need to investigate how to lock down windows 8.1 so that the user is restricted to the desktop only and only has access to a
    certain few applications.
    These PC's are in a domain and are used for either Accounting or POS.
    The software is what it is and changing the software is not an option. 
    Right now, the users log into XP machines. The desired programs auto-load and all is well.
    As of April 1st, the XP POS machines will no longer be PCI compliant. We prefer to step up to win 8.1 stations, but locking them down via group policy is proving to be difficult.
    We don't want third party tools. 
    Certainly this must be achievable via group policy.
    Any assistance will be greatly appreciated.
    Thanks 
    Jerry C
    (originally asked in answers.microsoft.com)

    Jerry
    I am sure you have but have you looked at kiosk mode?
    http://www.geek.com/microsoft/windows-8-1-kiosk-mode-locks-systems-to-a-single-app-1552963/
    http://blogs.msdn.com/b/hyperyash/archive/2013/10/25/enable-kiosk-mode-in-windows-8-1.aspx
    If Kiosk doesnt cut it the below thread has a bit about how to lock it down via GP.
    http://social.technet.microsoft.com/Forums/en-US/6c67d219-dba9-4de8-988f-ae46b19b2ccb/windows-81-kiosk-mode?forum=w8itproinstall
    Wanikiya and Dyami--Team Zigzag

Maybe you are looking for

  • What is preventing me from editing this PDF in Acrobat?

    I did some extensive editing of a form, and so chose to do it in FormsCentral.  When I finished my changes, I did a File - Save as PDF Form.  The outcome of this was the opening of Adobe Acrobat with the form.  This is the point that I added the thir

  • Moving HD boxes from room to room

    I have several HD fios boxes and a Standard box, too. I want to switch the standard box and an HD box. Along with their respective TVs. Can I just switch the boxes or is there anything else that needs to be done. Thanks

  • My mom gave me her old Ipad, how do I synch it to my account?

    How do I synch a new to me Ipad to my account?  When  plugged it in to my computer I was not triggered to synch like I have with previous devices.

  • OS X 10.5.8 to Snow leopard 10.6.8

    Hey guys, When installing snow leopard from os x 10.5.8, do I need to backup my data or it doesn't delete my files?

  • How to play musics by folder[Zen Wa

    Hello, recently got my Wav ,and while playing musics, i realised all my songs are jumbled up even when i categorise them in folder inside music folder. For example English; Male; Female; and etc. I wanted them to play folder by folder, is it possible