Differences between the "All" and "Default" security scopes

Author Message
jheaton558

  • Total Posts : 49
  • Scores: 0
  • Reward points : 18620
  • Joined: 9/23/2009
  • Status: offline
Differences between the "All" and "Default" security scopes Thursday, May 31, 2012 6:23 PM (permalink)
0
My co-worker setup our new CM12 enviroment, because he wanted a better understanding of it than what he had with 07.  I noticed today that the "All" security scope contains his account, and our SCCM service account.  I tried to add myself, but the option is greyed out.
 
Any big differences between these two scopes, other than the "All" scope is applied to everything by default?  Any way to change that from his account to mine?
 
#1
    bmason505

    • Total Posts : 3272
    • Scores: 246
    • Reward points : 80150
    • Joined: 1/23/2003
    • Location: Minneapolis, MN
    • Status: offline
    Re:Differences between the "All" and "Default" security scopes Friday, June 01, 2012 12:50 PM (permalink)
    0
    Under Administration\Security\Administrative Users, select your ID or user group & choose properties.  On the security tab, click the radio button to All instances.  That will give you All.
    Having said that, I recommend you apply this only for an empty group in AD which you place yourself into when you need such massive access.  Then you have another more limited scope and role for yourself.  Much like we treat domain admins.  That's a group I also recommend stay empty until you need it - then you put yourself in long enough to do some upper level function and then remove yourself.
    That being said, I know of a company with 10 people who all surf the net as domain admins, so ...  
    Brian Mason
    MCTS\MS MVP - ECM 
    http://www.mnscug.org/
     
    #2
      jheaton558

      • Total Posts : 49
      • Scores: 0
      • Reward points : 18620
      • Joined: 9/23/2009
      • Status: offline
      Re:Differences between the "All" and "Default" security scopes Friday, June 01, 2012 1:03 PM (permalink)
      0
      Brian,
       
      Thanks for the response.  When I follow your directions, Under the Security Scopes tab (I don't see a tab that only says Security) The "All instances of the objects that are related to the assigned security roles" radio button is greyed out.  The one below that "Only the instances of objects that are assigned to the specified security scopes and collections" radio button is selected.  The collections that are shown are All Systems, and All Users and User Groups.
       
      I just want to verify that by being in the Default security scope, I'm going to have all the privileges that I may need, and not have to come back and add collections as they are created, etc.
       
      #3
        bmason505

        • Total Posts : 3272
        • Scores: 246
        • Reward points : 80150
        • Joined: 1/23/2003
        • Location: Minneapolis, MN
        • Status: offline
        Re:Differences between the "All" and "Default" security scopes Friday, June 01, 2012 2:09 PM (permalink)
        0
        Looks like your friend would have to do that for you.
        Brian Mason
        MCTS\MS MVP - ECM 
        http://www.mnscug.org/
         
        #4
          Online Bookmarks Sharing: Share/Bookmark

          Jump to:

          Current active users

          There are 0 members and 1 guests.

          Icon Legend and Permission

          • New Messages
          • No New Messages
          • Hot Topic w/ New Messages
          • Hot Topic w/o New Messages
          • Locked w/ New Messages
          • Locked w/o New Messages
          • Read Message
          • Post New Thread
          • Reply to message
          • Post New Poll
          • Submit Vote
          • Post reward post
          • Delete my own posts
          • Delete my own threads
          • Rate post

          2000-2013 ASPPlayground.NET Forum Version 3.9