Questions about Groups Wheel & Admin

OK I have two systems. One is an iMac upgraded from Leopard to Snow Leopard. Its main hard drive has the following owner & group:
Owner: "system" (Read & Write)
Group: "admin" (Read & Write)
But on my Mac Pro's main drive it is like this:
Owner: "system" (Read & Write)
Group: "wheel" (Read & Write)
Note: The Mac Pro was a clean install of Snow Leopard from the full install disk, whereas the iMac was Leopard upgraded to Snow Leopard.
I have read in some places that in Snow Leopard they use "wheel" instead of "admin", but why would Apple choose to use such a cryptically named group as "wheel" when the use of a logical, sensical term such as "admin" would be much easier to understand to most users? Why is one Snow Leopard computer using the "admin" group whereas another is using the "wheel" group as the default group for the main hard drive? What is the correct group that the main boot drive should have for it (i.e. when you click on the hard drive on the desktop and do "get info" what should it say)?
I used Migration Utility to copy a user from my MacBook Pro to the Mac Pro. Then I logged in as Root on the Mac Pro and used this method (http://support.apple.com/kb/HT1428) to rename my user directory to be a new shortname, then create a new user with that shortname and point it at that folder (to fix some nagging permissions issues). Then I deleted the old user account. Then I renamed the new user account folder with the old shortname that it used to have, and created a new user with that name. But every time I create a folder it has the "Wheel" group... which seems like a security problem since anything I download into that folder will now be able to SU. Why would that be the default group?
In the old OS X (like 10.0, 10.1) there used to be "NetInfo Manager" where you could see all the users on a system and all the groups and change all that stuff, if you wanted to. In Leopard there was "Directory Utility" but it had much more limited features. In Snow Leopard, how do I pull up a list of all the users on a system and be able to edit their groups and all that stuff about them?

DaddieMac wrote:
V.K. wrote:
run the following command in terminal
sudo chown root:admin /
you'll have to enter your admin password (which you won't see). that's normal.
This will change the ownership on the hard drive to root:admin.
Why can't I just "Get Info" on the drive, and set its group to "admin" in there?
the whole GUI permissions management in Leopard and Snow leopard is very clunky and leaves a lot to be desired.
Can I just question why Apple has given us the ability to change the group in the "Get Info" box when really it doesn't do anything, and you still have to resort to using the Terminal and typing in non-plain-English commands that are merely relics of an operating system from 40 years ago that somehow still persists in our basement despite its lack of user friendliness?
what? SU?? wheel is the superuser group. by default only root belongs to it and nobody else. so having a wheel group on a folder does not create security issues.
what folders exactly have the wheel group? you home folder? as I said, folders created in any folder will inherit the group of that folder so maybe the wheel on your whole drive is doing this.
Well, even though I went into the "Get Info" box and took off "Wheel" from my root directory, still, when I make new folders on the root level of the drive, it creates them as being group "Wheel." Now, my understanding is that if I download a program and save it INTO that folder, then it would have the ability to execute as root because it will belong to the "Wheel" group -- am I not understanding this correctly? Thanks.
as I said, the GUI permission management is all messed up. you just keep running into various messed up aspects of it. this is another one. here is what happens.
when you remove a group completely from permissions using GUI it does not simply go away. it also incredibly changes to wheel.
you just don't see it because the permissions for the group are changed to none. so, for example, say, you have a file with the group staff and that group has read permissions to the file. you select that group in GUI permissions panel and use "-" to remove it. what should happen is that the group remains the same but it's permissions are set to 0. what does happen is that the group changes to wheel (which has group id=0) and its permissions are set to 0.
this is definitely a bug and a silly programming error. It's been around since Leopard. I reported it to Apple a long time ago.
so despite your hate of terminal and unix you are going to have to use them to fix the issue. get used to it. OS X is unix based and sometimes one has to use terminal to fix things. in this case there is no other way to do this. run the terminal command I gave you and it will fix the problem with new (but not already existing) folders at the top level of the hard drive. if you want to change the group on those you'll need to run similar commands for them too.

Similar Messages

  • A few questions about Group Policy development

    This post was originally in the Windows Development forum. Please note the following:
    This question is not about the application and management of GPOs. It's about how to develop a group policy.
    I know about Group Policy Preferences, please do not provide this as an answer.
    I create a custom group policy for an application.
    Recently the application developers allowed settings to be controlled via policy registry keys, in order to make these settings easier to set for Systems Administrators I have created a GPO. Unfortunately, there aren't that many resources
    I can find that help with Group Policy creation, so:
    Is there an easier way to create and edit admx/adml files rather than just a xml editor? Like a GUI front end?
    The vast majority of this applications settings are just a simple Boolean, is there any way to just use one base presentation element for multiple policies? or do I really have to create a presentation element for every single policy? :/
    As mentioned above, most settings are a simple Boolean, but with an additional enforce parameter. If you "enforce" the setting the user is blocked from changing the value. I was going to peg the setting Boolean to whether the policy was
    Enabled or Disabled and have an enforce check box in the policy itself (this would make it easier to just glance at the configured settings and get an idea). Unfortunately, when you disable a policy you cannot interact
    with its contents, so the enforce check box cannot be toggled. So I have two options:
    Have two policies for each setting eg: Disabled: Load printer settings with the document and
    Enabled: ENFORCE Load printer settings with the document
    OR what I have elected to do is just have the one policy with 2 check-boxes in it, one for the setting and one for the enforcement
    The former is both more complex to write for me and more time consuming to configure for the Administrator, the later is easier for me to write but still annoying to use. So my final question is: can I make it so, even though a policy is disabled, you can
    still toggle settings within the policy?

    Hi Thomas.
    > (this will set the default in the application) and then toggling whether
    > that setting is Enforced (unable for the user to modify it - disabling
    > it in the user interface).
    As said - that's not how policies are intended to work - they are always
    enforced. You are talking about preferences that have an optional
    "enforce" switch :) But doesn't matter for the remainder of this post.
    >  1. The presentation table contains hundreds of presentation tags that
    >     essentially are the same thing. From your response there is no way
    >     to make the GPO any easy to write? I can't just create one generic
    >     presentation that multiple policies can use? I have to create a
    >     presentation for every. single. policy.?
    I'd sugggest to use ADM instead of ADMX. Much easier to write and
    maintain, and copy/paste works very well in ADM :)
    https://msdn.microsoft.com/library/bb742499.aspx
    >  2. Because of how the settings are set, as mentioned in my earlier
    >     post, I have chosen to have each policy contain two check boxes.
    >     Each setting could be set to the following:
    >      1. True
    >      2. False
    >      3. True and Enforced
    >      4. False and Enforced
    What elements you need depends on the registry values your application
    is expecting/checking. I'd suggest a radio button (enabled/disabled) and
    a check box "enforced".
    >     there a way for a Disabled policy to also have settings that can be
    >     modified in Group Policy Management? Or can only Enabled policies be
    >     modified?
    You cannot edit what a disabled GPO does, but you can define it
    (VALUEOFF in ADM files if I recall correctly).
    >     well because it would make it easier for them to read the GPO. But I
    >     think you are saying this is not possible.
    Yes, it isn't. It still - at least to me - is a slight misunderstanding
    of "preferences" versus "policies" :)
    Greetings/Grüße,
    Martin
    Mal ein
    gutes Buch über GPOs lesen?
    Good or bad GPOs? - my blog…
    And if IT bothers me -
    coke bottle design refreshment (-:

  • Question about grouping.

    Hello ,
    I have a problem in grouping my data the way i want , i have 2 tables : Orders & Modifiedorders ,
    the Modifiedorders holds the orderid and some data about how the order is modified , sometimes the orderid
    in the Modifiedorders table can repeat if the data modified is of different types , like modify the quantity or price ..
    Now what i want is to make a report that displays some data from the Orders table and when there are
    record(s) from the modifiedorders table it should be displayed at the left for example , but without repeating the orderid .
    What i tried is creating an outerjoin query between the 2 tables , and using the wizard i created a report with the group left style and had the Orderid as the grouping field , but still the orderid repeats . what should i do ?
    Thanks in advance..

    What i tried is creating an outerjoin query between the 2 tables , and using the wizard i created a report with the group left style and had the Orderid as the grouping field , but still the orderid repeats . what should i do ?You did the right thing. Reuse Reports Wizard.
    What's your query?

  • Newbie with question about mouse wheel button

    Sorry in advance if this is too simple, but I'm trying to create an interactive website that requires scene switching by way of the mouse wheel button.
    I'm creating mutliple interactive labeled images that I want to be able to scroll through by using the mouse wheel button but I don't know the action script code.
    Any help?
    Furna.

    Hi Kglad I have a small query about your code correct me if I am wrong some where. You used following lines to
    create  movie clip,
    set focus on it,
    and add event listener to it.
    the lines are
    var tl:MovieClip = this
    stage.focus = tl
    tl.addEventListener(MouseEvent.MOUSE_WHEEL,f);
    Now say I have a button on stage and I click it once. the focus will change to the button. and hence we will have to set the focus again to tl after processing button click.  am I correct on this?
    we can alternatively use
    stage.addEventListener(MouseEvent.MOUSE_WHEEL,f);
    which will always listen to the scroll event no matter where the focus is, or is there some problem which might occur due to this?

  • Simple question about WLI and admin server

    Hello,
    I have a domain with 3 servers in 2 machines. 2 servers forms the cluster and the other one is the admin server.
    When a process finish, the WLI core execute a setStatus on JMX component of type ProcessConfiguration. This type of component is only deployed (in my installation) in the admin server. So the Integrarion cluster service depends on admin server...if I stop the admin servers all the process invocations fails...
    I have tried to disable the process tracking data using wli console without results...
    How I can disable this behavior?
    Is there any way to deploy this type of component (ProcessConfiguration JMX) in the cluster?
    Thanks
    WL8.1 with SP5, WLI8.1

    Hello,
    You can start TOMCAT jsp engine on PC B, it will start on port 8080 on B. And now redirect the requests from Apache in PC A using the mod_rewrite. Look at the following link on how to redirect the requests, give the redirect url as PCB:8080
    http://httpd.apache.org/docs/misc/howto.html#redirect
    HTH
    Vamsi kundeti

  • Question about GROUP BY and HAVING

    Good afternoon,
    I have the following query which returns the desired result (set of students who take CS112 or CS114 but not both). I wanted to "condense" it into a single SELECT statement (if that is at all possible - DDL to execute the statement is provided at the end of this post):
    -- is this select distinct * and its associated where clause absolutely
    -- necessary to obtain the result ?
    select distinct *
      from (
            select s.sno,
                   s.sname,
                   s.age,
                   sum(case when t.cno in ('CS112', 'CS114')
                            then 1
                            else 0
                       end)
                     over (partition by s.sno) as takes_either_or_both
              from student s join take t
                               on (s.sno = t.sno)
      where takes_either_or_both = 1
    ;The following looked reasonable but, unfortunately unsuccessful:
      Window functions not allowed here (in Having Clause)
    select max(s.sno),
           max(s.sname),
           max(s.age),
           sum(case when t.cno in ('CS112', 'CS114')
                    then 1
                    else 0
               end)
             over (partition by s.sno) as takes_either_or_both
      from student s join take t
                       on (s.sno = t.sno)
    group by s.sno
    having sum(case when t.cno in ('CS112', 'CS114')
                    then 1
                    else 0
               end)
             over (partition by s.sno) = 1
    Invalid identifier in Having clause
    select s.sno,
           s.sname,
           s.age,
           sum(case when t.cno in ('CS112', 'CS114')
                    then 1
                    else 0
               end)
             over (partition by s.sno) as takes_either_or_both
      from student s join take t
                       on (s.sno = t.sno)
    group by s.sno, s.sname, s.age
    having takes_either_or_both = 1
    ;I have searched for a document that completely defines the sequence in which the clauses are executed. I have found tidbits here and there but not something complete. I realize that my running into problems like this one is due to my lack of understanding of the sequence and the scope of the clauses that make up a statement. Because of this, I cannot even tell if it is possible to write the above query using a single select statement. Pardon my bit of frustration...
    Thank you for your help,
    John.
    DDL follows.
            /* drop any preexisting tables */
            drop table student;
            drop table courses;
            drop table take;
            /* table of students */
            create table student
            ( sno integer,
              sname varchar(10),
              age integer
            /* table of courses */
            create table courses
            ( cno varchar(5),
              title varchar(10),
              credits integer
            /* table of students and the courses they take */
            create table take
            ( sno integer,
              cno varchar(5)
            insert into student values (1,'AARON',20);
            insert into student values (2,'CHUCK',21);
            insert into student values (3,'DOUG',20);
            insert into student values (4,'MAGGIE',19);
            insert into student values (5,'STEVE',22);
            insert into student values (6,'JING',18);
            insert into student values (7,'BRIAN',21);
            insert into student values (8,'KAY',20);
            insert into student values (9,'GILLIAN',20);
            insert into student values (10,'CHAD',21);
            insert into courses values ('CS112','PHYSICS',4);
            insert into courses values ('CS113','CALCULUS',4);
            insert into courses values ('CS114','HISTORY',4);
            insert into take values (1,'CS112');
            insert into take values (1,'CS113');
            insert into take values (1,'CS114');
            insert into take values (2,'CS112');
            insert into take values (3,'CS112');
            insert into take values (3,'CS114');
            insert into take values (4,'CS112');
            insert into take values (4,'CS113');
            insert into take values (5,'CS113');
            insert into take values (6,'CS113');
            insert into take values (6,'CS114');

    Hi, John,
    Just use the aggregate SUM function.
            select s.sno,
                   s.sname,
                   s.age,
                   sum(case when t.cno in ('CS112', 'CS114')
                            then 1
                            else 0
                       end) as takes_either_or_both
              from student s join take t
                               on (s.sno = t.sno)
           GROUP BY  s.sno,
                    s.sname,
                  s.age
           HAVING  sum(case when t.cno in ('CS112', 'CS114')
                            then 1
                            else 0
                       end)  = 1;Analytic functions are computed after the WHERE- and HAVING clause have been applied. To use the results of an analytic fucntion in a WHERE- or HAVING clause, you have to compute it in a sub-query, and then you can use it in a WHERE- or HAVING clause of a super-query.

  • LR 1.4 Question about Group Edit Capture Time

    Hey guys... working my way through...
    Was wondering -- when I highlight a group of files -- and then go to the Metadata Menu and choose "Edit Capture Time" -- why doesn't it change the date of all the High-Ligghted Photos?
    I am obviously doing something wrong... Can someone please tell me who to di it right?
    THANKS!!

    ambienttroutmask wrote:
    It's a while since I used LR 1, but I think it was the same....to write time changes to RAW files, other than DNG's, you need to enable this in catalog settings. in metadata write changes into propitiatory RAW files. LR is very reluctant to write anything into propitiatory files (and rightly so), best to convert them to DNG's.
    actually - i'm kinda confused.
    all my images are DNG's.
    All I want to do is take a group of photos I took in 2002 [that all have bad dates from different decades somehow] and correct a group of say 130 files at a time to a specific day from all the various days they are mistakenly showing in Capture Time.
    But when I highlight a group of say 30 files and choose to EDIT CAPTURE TIME -- only 1 or maybe a couple of files change -- the rest stay.
    iPhoto allowed me to Batch Change a group of photos from various dates to 1 single date -- but I am getting the impression LR 1.4 does not have the ability to do this.

  • Quick question about GROUP BY

    Hello guys,
    I was wondering if anybody can shed the light on this? It's not very important. I'm just being curious here.
    Imagine I have the following table:
    CREATE TABLE my_table
      n NUMBER(15)
    INSERT INTO my_table SELECT level FROM dual CONNECT BY LEVEL <= 10;I know I can do this
    SELECT 'MY_TABLE',
           (SELECT COUNT(*) FROM my_table)
      FROM dual;To get the name of the table and how many records the table has. Because DUAL table has only one record it will return the correct result.
    But I don't understand why the following query returns the correct result:
    SELECT 'MY_TABLE',
           (SELECT COUNT(*) FROM my_table)
      FROM my_table
    GROUP BY NULL;If I remove the GROUP BY clause, I will have 10 records because my original table has 10 records. But how is it possible to GROUP BY NULL? Actually, you can group by on anything (1, 'HELLO'...) and it will return the correct result.
    So, can anyone tell me how does this make sense??
    Thanks in advance,

    Hi,
    user13117585 wrote:
    Hello guys,
    I was wondering if anybody can shed the light on this? It's not very important. I'm just being curious here.
    Imagine I have the following table:
    CREATE TABLE my_table
    n NUMBER(15)
    INSERT INTO my_table SELECT level FROM dual CONNECT BY LEVEL <= 10;I know I can do this
    SELECT 'MY_TABLE',
    (SELECT COUNT(*) FROM my_table)
    FROM dual;To get the name of the table and how many records the table has. Because DUAL table has only one record it will return the correct result.The fact that dual has only one row explains why the result set has one row. How many columns and what is in those columns doesn't depend on dual in any way.
    But I don't understand why the following query returns the correct result:
    SELECT 'MY_TABLE',
    (SELECT COUNT(*) FROM my_table)
    FROM my_table
    GROUP BY NULL;If I remove the GROUP BY clause, I will have 10 records because my original table has 10 records. But how is it possible to GROUP BY NULL? Actually, you can group by on anything (1, 'HELLO'...) and it will return the correct result.
    So, can anyone tell me how does this make sense??Right. "GROUP BY x" means the output will have 1 row for each distinct value of x. (NULL is treated like a value in this case.) So how many distinct values of NULL are there, or how many distinct values of 1, or 'HELLO', or any constant? There's only 1 value, constants, as the name implies, never change values. So if you GROUP BY any constant, the result set will have exactly one row.
    Thanks in advance,

  • Questions about Mapping GL Accounts to Group Accounts

    Hi,
    I have some questions about mapping gl accounts to group accounts while configuring OBIEE APPS 7.9.6.3 with EBS R12 as a source:
    FIRST QUESTION.-
    For file file_group_acct_codes_ora.csv, I have the following accounts from my customer:
    101101 - Caja Administrativa
    101102 - Fondo Revolvente
    101103 - Caja de Cambios
    101104 - Efectivo en cajero
    This group of accounts is named CASH, now my customer said that this group begins in 101101 and ends in 101199 but in this moment only have this 4 accounts in GL, the rest of the accounts, I mean 101105-101199 are not used right now, they are gonna used in the future.
    So, my question is, in file_group_acct_codes_ora.csv how I need to put this group:
    In this way:
    CHART OF ACCOUNTS ID,FROM ACCT,TO ACCT,GROUP_ACCT_NUM
    50308,101101,101104,CASH
    Or in this way:
    CHART OF ACCOUNTS ID,FROM ACCT,TO ACCT,GROUP_ACCT_NUM
    50308,101101,101199,CASH
    I mean, is there any problem if I use the second way, or is necessary to do it in the first way, and why?
    SECOND QUESTION.-
    For file file_group_acct_names.csv, when I update with a new group of accounts, is there any rule or size boundary for GROUP_ACCOUNT_NAME?
    THIRD QUESTION.-
    For file_group_acct_names.csv, what is the value in column LANGUAGE? I mean, is EBS language?, DB language?, server language?
    I hope that someone can help me, because I need to clarify this and don't do the first full load and this load ends with error because of this.
    Regards,
    Arnulfo

    I'll take some broad swipes at this and let the smarter people come fill in the details.
    We have a true 1:1 setup in our office and have moved to PHDs as a means of protecting against downtime. The thinking is that we will have a spare machine lying around with our base installation ready to go. If a user's machine fails we'll replace it with the spare machine, let it sync the user directory from the server, and we're back in business. It's no substitute for a real backup system, but it potentially avoids having to run a restore from your backups. It also reduces network traffic compared to plain networked homes, and still lets your users work if the server goes down, but provides the benefits of centralized management. John DeTroye wrote a nice article about this.
    If you've already got data on your "client" Mac you will need to move it onto the server. PHDs will download data from the server to the client on the first sync, but will not upload a complete home directory from the client to an empty directory on the server. You'll find some posts in this forum discussing how people have gone about migrating data prior to that first sync.
    WGM allows you to establish exclusions for stuff you don't want to sync.
    One thing to watch out for in the scenario you describe is the so-called "rabbit effect." Assume Bob uses Mac1 as his primary machine. If one day he logs into Mac2 his home directory will be downloaded to Mac2. Once he returns to Mac1 he'll still be cluttering up Mac2 with his data. If he logs into Mac3 the next day and Tom and Sue are also periodically logging into different machines, you can see how you'll end up with a mess pretty quickly.
    Hope this helps.

  • Question about Everyone Group in SharePoint 2013

    Hi,
    I have couple of question about EVERYONE group below,
             - As per the best practice which Group we should use instead of EVERYONE group in Sharepoint ?
             - What is the difference between Everyone and All Authenticated Users Group
    We have added Everyone Group in different sites, now the question is if we hide this group showing up in sharepoint people picker, is there any impact interms of current site?
             - Is there any way we can hide Everyone group showing up in the people picker only for the site / Site Collection level.
    Please help.
    Thanks
    srabon

    There is no functional difference between the Everyone group and All Authenticated Users (after Active Directory has been upgraded to Server 2003 native schema).
    I'm not aware of any function to hide the group from the People Picker.
    Trevor Seward
    Follow or contact me at...
    &nbsp&nbsp
    This post is my own opinion and does not necessarily reflect the opinion or view of Microsoft, its employees, or other MVPs.

  • When do I use user group "wheel"?

    Hello,
    I have the following question: What exactly is the user group "wheel" for and when do I use it (instead of "admin", for example)? Background to the question is, I recently noticed that some applications needed to be updated regarding ownership and ACLs.
    I had installed them while working as a non-admin user by drag and drop, authenticating as an admin user (which is short named "admin", too) when asked to identify as one. The apps were installed alright, but the ownership was set to the non-admin user, while the group was "admin". This caused some problems with BOINC, for instance, which I tried to fix by updating ownership and ACL, accordingly.
    When checking other apps that were installed with Mac OS X I noticed that most belonged to "root" (aka "System") and group "wheel" instead of "admin". This lets me wonder about when to use which group.
    Does anyone know about the backgrounds of this?
    Thank you in advance
    Jim

    Regarding your original question:
    "I had installed them while working as a non-admin user by drag and drop, authenticating as an admin user (which is short named "admin", too) when asked to identify as one."
    Okay, a couple of things here.
    First of all, for the most part, whenever you copy files in the Finder, the copied files take on the ownership of the person doing the copying (there's one exception which we'll see in the next paragraph). Since you were in a non-admin account, the Finder realized that in order to modify the /Applications/ folder, you'd need to first authenticate with an administrator name and password to obtain permission. Once permission was granted, the copied files took on the ownership of the user doing the copying (the non-admin user).
    "The apps were installed alright, but the ownership was set to the non-admin user, while the group was "admin"."
    Let's say you have a folder "ExampleFolder" whose owner is "root" and group is "admin". When you copy an item into the ExampleFolder, the copied item will take on the group permission value from the parent folder. That's why the item you copied had a group of "admin" (since the /Applications/ folder's group is "admin").
    "When checking other apps that were installed with Mac OS X I noticed that most belonged to "root" (aka "System") and group "wheel" instead of "admin"."
    Hmm, as far as I can tell, that's not true. Almost all of the applications in the /Applications/ folder will be drwxrwxr-x, root-owned, and group of "admin". Note that there is a display bug in the Ownership & Permissions section of the Finder's Inspector-style Info window in Tiger. The values shown in the pop up menus for owner and group do not update dynamically as you change your selection. Instead, they continue to show the owner and group of the original item on which you first opened the Inspector panel. So, for example, if you selected the /System/ folder, which has an owner of root and group of wheel, and then opened the Inspector window, any subsequent items you selected (such as applications in the /Applications/ folder) would still appear to have a group of "wheel". (The regular style Finder Get Info windows are fine).
    Hope this helps.....
    Dual 2.7 GHz PowerPC G5 w/ 2.5 GB RAM   Mac OS X (10.4.3)  

  • A question about CA Role Seperation

    Hello
    Can someone please help me with the following question regarding CA Role Separation (thanks in advance)
    I understand by default the 'Local Administrator' or 'Local Administrators Group' have certain high privileges on the CA itself.
    I understand enabling 'Role Separation' stops a security principle (e.g. user) being a member of more than one of the pre-defined CA Role Based Administration roles. For example if Role Separation is enabled you cannot have both Audit
    and Backup rights.
    If the above is correct, when you enable Role Separation does this also take away the default privileges the Local Administrator (and members of the Local Administrators Group) have on the CA?
    Or
    Does Role Separation simple stop the Local Administrator (or members of the Local Administrators Group) being assigned more than one of the CA Role Based roles (as above) but thereby still allow high privileges to the CA in any event.
    The reason I ask is by default I believe Domain Admins group is automatically made a members of the Local Administrators Group on Domain Joined computers (and thereby the CA Server).
    I do not want Domain Admins or Enterprise Admins having Rights to the CA (e.g. be able to perform CA tasks).
    Therefore do I need to perform 'extra' tasks over and about enabling Role Separation (e.g. restricting membership of the local administrators group) to achieve the security I want?
    Thanks All
    AAnotherUser__
    AAnotherUser__

    Hi,
    Based on your description, you don’t want Domain Admins or Enterprise Admins having rights to the CA, which cannot be achieved.
    That’s because members of local administrators group on a CA can disable role separation. Even if we remove the Domain Admins group from the local administrators group, Domain Admins still can add them back through Restricted Groups group policy.
    Here are some references below for you:
    Role Separation
    http://technet.microsoft.com/en-us/library/cc773161(v=WS.10).aspx
    Restricted Groups Policy Settings
    http://technet.microsoft.com/en-us/library/cc756802(v=WS.10).aspx
    Best Regards,
    Amy

  • Some questions about Muse

    First of all, I would like to say that I am very impressed with how well Muse works and how easy it was to create a website that satisfies me. Before I started a daily updated website I thought I would encounter many problems I will not be able to solve. I have only had a few minor issues which I would like to share with you.
    The most problems I have with a horizontal layouts (http://www.leftlane.pl/sty14/dig-t-r-3-cylindrowy-silnik-nissana-o-wadze-40-kg-i-mocy-400- km.html). Marking and copying of a text is possible only on the last (top) layer of a document. The same situation is with widgets or anything connected with rollover state - it does not work. In the above example it would be perfect to use a composition/tooltip widget on the first page. Unfortunately, you cannot even move the cursor into it.
    It would be helpful to have an option of rolling a mouse to an anchor (like in here http://www.play.pl/super-smartfony/lg-nexus-5.html and here http://www.thepetedesign.com/demos/onepage_scroll_demo.html).  I mean any action of a mouse wheel would make a move to another anchor/screen. It would make navigation of my site very easy.
    Is it possible to create a widget with a function next anchor/previous anchor? Currently, in the menu every button must be connected to a different anchor for the menu to be functional.
    A question about Adobe Muse. Is it possible to create panels in different columns? It would make it easier to go through all the sophisticated program functions.
    The hits from Facebook have sometimes very long links, eg.
    (http://www.leftlane.pl/sty14/mclaren-p1-nowy-krol-nurburgring.html?fb_action_ids=143235557 3667782&fb_action_types=og.likes&fb_source=aggregation&fb_aggregation_id=288381481237582). If such a link is activated, the anchors in the menu do not work on any page. I mean the backlight of an active state, which helps the user to find out where on page they currently are. The problem also occurs when in the name of a html file polish fonts exist. And sometimes the dots does not work without any reason, mostly in the main page, sometimes in the cooperation page either (http://www.leftlane.pl/wspolpraca/). In the first case (on main page), I do not know why. I have checked if they did not drop into a state button by accident,  moved them among the layers, numbered them from scratch and it did not help. In the cooperation page, the first anchor does not work if it is in Y axle set at 0. If I move it right direction- everything is ok.
    The text frame with background fill does not change text color in overlay state (http://www.leftlane.pl/sty14/nowe-mini-krolestwo-silnikow-3-cylindrowych.html). I mean a source button at the beginning of every text. I would like a dark text and a light layer in a rollover, but  the text after export and moving cursor into it does not change color for some reason.
    I was not sure whether to keep everything (whole website) in one Muse file (but I may be mistaken?). I have decided to divide it into months. Everyone is in a different Muse file. If something goes wrong, I will not have any trouble with an upload of a whole site, which is going to get bigger and bigger.
    The problem is that every file has two master pages. Everything works well up to the moment when I realize how many times I have to make changes in upper menu when I need to add something there. I have already 5 files, every with 2 masters. Is there any way to solve this problem? Maybe something to do with Business Catalyst, where I could connect a menu to every subpage independently, deleting it from Muse file? Doing so I would be able to edit it everywhere from one place. It would make my work much easier, but I have no idea jendak how to do it.
    The comments Disqus do not load, especially at horizontal layouts  (http://www.leftlane.pl/sty14/2014-infiniti-q50-eau-rouge-concept.html). I have exchanged some mails and screenshots with Disqus help. I have sent them a screenshot where the comments are not loaded, because they almost never load. They have replied that it works at their place even with attached screenshot. I have a hard time to discuss it, because it does not work with me and with my friends either. Maybe you could fix it? I would not like to end up with awful facebook comments ;). The problem is with Firefox on PC and Mac. Chrome, Safari and Opera work ok.
    YouTube movie level layouts do not work well with IE11 and Safari 7 (http://www.leftlane.pl/sty14/wypadki-drogowe--004.html). The background should roll left, but in the above mentioned browsers it jumps up. Moreover the scrolling with menu dots is not fluent on Firefox, but I guess it is due to Firefox issues? The same layout but in vertical version rolls fluently in Firefox (http://www.leftlane.pl/sty14/polskie-wypadki--005.html).
    Now, viewing the website on new smartphones and tablets. I know it is not a mobile/tablet layout, but I tried to make it possible to be used on mobile hardware with HD (1280) display. I mean most of all horizontal layouts (http://www.leftlane.pl/sty14/2015-hyundai-genesis.html), where If we want to roll left, we need to roll down. Is there a way to make it possible to move the finger the direction in which the layout goes?
    On Android phones (Nexus 4, Android 4.4.2, Chrome 32) the fade away background effect does not work, although I have spent a lot of time over it (http://www.leftlane.pl/lut14/koniec-produkcji-elektrycznego-renault-fluence-ze!.html). It is ok on PC, but on the phone it does not look good. A whole picture moves from a lower layer instead of an edge which spoils everything.
    This layout does not look good on Android (http://www.leftlane.pl/sty14/nowe-mini-krolestwo-silnikow-3-cylindrowych.html#a07). The background does not fill the whole width of a page. There are also problems with a photo gallery, where full screen pictures should fill more of a screen.
    Is it possible to make an option of  scroll effects/motions for a fullscreen slideshow widget thumbnails (http://www.leftlane.pl/sty14/2014-chevrolet-ss%2c-rodzinny-sedan-z-415-konnym-v8.html#a06)? It would help me with designing layouts. Currently, it can go from a bottom of a page at x1 speed or emerge (like in this layout) by changing opacity. Something more will be needed, I suppose.
    Sometimes the pictures from gallery (http://www.leftlane.pl/sty14/2014-chevrolet-ss%2c-rodzinny-sedan-z-415-konnym-v8.html#a06 download very slowly. The website is hosted at Business Catalyst. I cannot state when exactly it happens, most of the time it works ok.
    I really like layouts like this (http://www.leftlane.pl/sty14/2014-chevrolet-ss%2c-rodzinny-sedan-z-415-konnym-v8.html#a03). On the top is a description and a main text, and the picture is a filled object with a hold set at the bottom edge. That is why there is a nice effect of a filling a whole screen- nevertheless the resolution that is set. It works perfect on PC, but on Android the picture goes beyond the screen. You can do something about it?
    In horizontal layouts (http://www.leftlane.pl/sty14/dig-t-r-3-cylindrowy-silnik-nissana-o-wadze-40-kg-i-mocy-400- km.html) holding of a filling object does not work. Everything is always held to upper edge of a screen regardless the settings. Possibility of holding the picture to the bottom edge or center would make my work much easier.
    According to UE regulations we have to inform about the cookies. I do not know how to do it in Muse. I mean, when the message shows up one time and is accepted, there would be no need to show it again and again during another visit on the website. Is there any way to do it? Is there any widget for it maybe?
    The YouTube widget sometimes changes size just like that. It is so when the miniature of the movie does not load, and the widget is set to stroke (in our case 4 pixels, rounded to 1 pixel). As I remember ( in case of a load error) it extends for 8 pixels wide.
    Last but not least - we use the cheapest hosting plan in Business Catalyst. The monthly bandwidth is enough, although we have a lot of pictures and we worried about it at first. Yet we are running out of the disk storage very quickly. We have used more than a half of a 1 GB after a month. We do not want to change BC for a different one, because we like the way it is connected with Muse. But we do not want to buy the most expensive package - but only this one has more disk space. We do not need any other of these functions and it would devastate our budget. Do we have any other option?
    I’m using Adobe Muse 7.2 on OS X 10.9.1.
    and I'm sending Muse file to <[email protected]>

    Unfortunatley, there is no way to get a code view in Muse. I know quite a few people requested it in the previous forum, but not really sure where that ended up. Also, you may not want to bring the html into DW unless you only have 1 or 2 small changes 2 make. Two reasons. First, it isnt backwards compatible, so if you are planning on updating that site in Muse, you will need to make those changes in DW everytime you update. Second, by all accounts the HTML that Muse puts out is not pretty or easy to work with. Unlike you, I am code averse, but there was a lenghty discussion on the previous forum on this topic. I know they were striving to make it better with every release, just not sure where it is at this point.
    Dont think I am reading that second question right, but there was a ton of info on that old site. You may want to take a look there, people posted a ton of great unique solutions, so it worth a look.
    Here is the link to the old forums- http://support.muse.adobe.com/muse

  • Questions about using Bitlocker without TPM

    We currently use Bitlocker to encrypt our Windows 7 computers with TPM. Now we are looking at encrypting some Windows 7 computers without a TPM. I see how to change the group policy setting to allow Bitlocker without a TPM. I have looked at a lot of other
    threads and I have a few questions about how the Bitlocker without TPM works.
    1) I see a USB drive containing a key is required for Bitlocker configurations without a TPM, say the end user loses this USB drive, what are the recovery options for their computer? 
    This article seems to indicate that without the USB drive connected, you are unable to even access recovery options http://blogs.technet.com/b/hugofe/archive/2010/10/29/bitlocker-without-tpm.aspx
    We have recovery backed up to AD when Bitlocker is enabled, but how could we do this recovery on a computer on computer where it's USB is lost? Would we have to remove the HD itself and attach it to another computer to access?
    2) After enabling Bitlocker on a computer without a TPM and using the USB Drive for the key, is there a way to also add a PIN or password protection at bootup?

    Hi,
    Sorry for my dilatory reply, 
    Configuring a startup key is another method to enable a higher level of security with the TPM. The startup key is a key stored on a USB flash drive, and the USB flash drive must be inserted every time the computer starts. The startup key is used to provide
    another factor of authentication in conjunction with TPM authentication. To use a USB flash drive as a startup key, the USB flash drive must be formatted by using the NTFS, FAT, or FAT32 file system.
    You must have a startup key to use BitLocker on a non-TPM computer.
    From: http://technet.microsoft.com/de-de/library/ee449438(v=ws.10).aspx#BKMK_Key
    For more Q&A about BitLocker, you can refer to the link above.
    hope this is helpful.
    Roger Lu
    TechNet Community Support

  • A lot of questions about my MacBook Air

    I am really new to re-using Apple computers.The last time I used an Apple computer was back in 1987 when the school and my family had Apple IIGS computers. I have been using PC's which reqiure Microsoft. I a lot of have questions (10 questions) about my MacBook Air and I hope you good people can and will help me.
    Product: MacBook Air
    Operating System: Mac OS X Version 10.7.4
    1) I Downloaded MacKeeper because I was fooled. I had a bad feeling just before I Downloaded it and I should have listened to my heart. However, I didn't buy it or fully Install it. It was like a test run and then they wanted me to pay almost $100 for it. Thankfully, I didn't because I read it is Malware. I spoke with an Apple Tech at Apple Care and he helped me get rid of it (or so we think). I don't see it anymore on my computer. I read it can slow down your computer. How can you tell if it's really off of the computer?
    2) When I open "Finder" and I see that there are people Sharing my computer with me. I went into AirDrop and it reads, "Other people can see your Mac as (my name) MacBook Air when their computer is nearby." I bought a HotSpot and while it's turned on and I selected it as my WI-FI connection I thought it would  get rid of these people, protect what I type, me, my items, computer, etc. But it didn't.  
    I didn't know that I have to buy a exteral CD and/or DVD Player in order to connect to the brand new Modem and Router in one by NetGear. I am so used to PCs and the CD/DVD Players being built inside.
    The people at Apple Store told me that there is an internal modem inside, but I don't know how to find it and what to do then.  Should I use a Firewall?, An AntiVirus, AntiMalware, AntiSpyware, etc. Apple Care tech told me I don't need to get an AntiVirus.
    3) Is there a new kind of Wireless Modem and Router that doesn't require a CD-ROM?
    4) When I travel or fly and I am not close to home I was told by Best Buy and Sprint that I had to buy a mobile HotSpot to use the computer (WI-FI) safely. As I typed, I have one. But it's pretty expensive and only gives me 1 hour and 15 minutes per day to Stream. What can I do to use this computer safely Online when I am out of range from a Modem and Router? What do people do when they travel on airplanes?  
    5) This compter won't let me use "Raid." I think you have to have a newer version. I hard about Raid on the radio from Leo (can't recall his last name) who's a Tech expert.
    6) Should I buy a ZipDrive? Apple Store Tech told me that I didn't need a ZipDrive. I just remember the episode of HBO's "Sex and The City" when Carrie looses everything because her copy crashed. Now, of course, I know that's a fictional show, but with PC's and Microsoft I have lost everything when it crashed, frooze up, etc. I know there's iClouds. I heard about Carbonite, but I have read the Pros and Cons about it. Mostly they are Cons about it. I just don't want to do anything wrong and mess up this computer.
    7) Should I buy a new Printer/Copier/Scanner because mine is an HP. It's not new, but it works. I even have a CD-ROM for Macs. What about the new product called, "Neat"?
    8) Is there a special product that I should buy to do Online Banking and/or other important stuff?
    9) I saw and read about iWork in the Apps Store and it sounds cool. I still have alot of friends and colleagues who still use Microsoft. Is iWork good to use? Should I Download it from the Apple Apps Store or can a buy it at Apple? Is there another Word Processing Program that is great and user friendly and will work with Macs and PCs?
    10) Should I Update the OS with OS X Mountian Lion Pro from the Apple Apps Store or buy it at Apple Store?
    In advance, I wish to thank you in this Apple Support Communites for your help.  Have a safe and happy holiday weekend!

    1) Here are instructions for removing MacKeeper. Since it mostly consists of manually looking for folders and specific files, if you follow the instructions you either fail to find what you are told to find (because your AppleCare guide gave you complete instructions which you followed) or you'll find some additional files that need to be replaced.
    2 & 3) I assume you are looking at the sidebar of a Finder window and seeing Shared and computers under it. Those are computers that you can potentionally share. To do so you'd need an account on their computer and a password. They are not sharing your computer.
    AirDrop allows you to create an adhoc network for filesharing and it only functions when you have selected the AirDop item in the SideBar. Actually doing that merely announces to computers in the same network node that your computer is available for a file to be sent to. Even then you have to explicitly allow the file to be downloaded to your computer. Similarly you'd be able to see other computers with AirDrop selected and be able to send them a file - which they'd have to accept.
    The only reason your NetGear Router comes with a CD is to install and run their 'easy' step by step configuration program. It can also be done manually with a browser. Read the manual to find the IP address you must enter to access the router's configuration menu. Apple's WiFi routers don't require a CD to install the software because the configuration software is already on your computer.
    I do have my firewall turned on. AntiVirus software isn't a bad idea - I use Sophos having tested it for a review for our local User Group and I found I liked it better than ClamAVx which is what I'd been using before. Both are free.
    4) I think you were scammed by Sprint and BestBuy. I use hotel, coffee shop, and restaurant WiFi spots and have for years. However, because they can be unsecured, I do not shop online or bank when I'm using them. I also use 1Password and don't reuse passwords so even if a sniffer should grab an account and password that's all it would get - one account.
    5) Raid doesn't really make sense with a MacBook Air - a RAID involves 2 or more disks being used as if they were one.
    6) Zip drive? No. External hard drive - yes. It isn't a question of if a computer's hard drive will malfunction, it is when. OWC has a nice selection of external drives and the Mac has a built in backup system called TimeMachine. Due to the way TimeMachine works, I've found that your TimeMachine drive should be at least twice as large - and preferably 3-4 times as large as the data you are backing up.
    7) if your printer works and it has Mountain Lion drivers, why replace it?
    8) Online banking is done with a browser - Use Safari or FireFox
    9) If trading files with Windows users is important Mac: Office is your best bet. If not, iWork, Mac:Office, or LibreOffice are all good possibilities.
    10) you can only buy Mt Lion via the App Store.

Maybe you are looking for