8.1 Built-in Roles

Built-in assistant administrator roles provide immediate access to a set of commonly used powers. You can extend your current security configuration by using these default roles to delegate power to specific user accounts or other groups.

These roles contain the powers required to perform common administration tasks. For example, the DRA Administration role contains all the powers required to manage objects. To use these powers, however, the role must be associated with a user account or an assistant administrator group and the managed ActiveView.

Because built-in roles are part of the default delegation model, you can use the built-in roles to quickly delegate power and implement security These built-in roles address common tasks you can perform through the DRA user interfaces. The following sections describe each built-in role and summarize the powers associated with that role.

8.1.1 Azure Active Directory Management

Azure Contact Administration

Provides all the powers required to create, modify, delete, and view properties of an Azure contact. You can assign this role to all assistant administrators who are responsible for managing Azure contacts.

Azure Group Administration

Provides all the powers required to manage Azure groups and Azure membership.

Azure User Administration

Provides all the powers required to create, modify, delete, enable, disable, and view properties of an Azure user. Assign this role to assistant administrators responsible for managing Azure users.

Azure Guest User Administration

Provides all the powers required to manage an Azure guest user. Assign this role to assistant administrators responsible for managing an Azure guest user.

8.1.2 Administration

Contact Administration

Provides all the powers required to create a new contact, modify contact properties, or delete a contact. Assign this role to assistant administrators responsible for managing contacts.

DRA Administration

Provides all powers to an assistant administrator. This role gives a user the permission to perform all administration tasks within DRA. This role is equivalent to the permissions of an administrator. An assistant administrator associated with the DRA Administration role can access all Directory and Resource Administrator nodes.

gMSA Administration

Provides the powers required to create, modify, delete, and view properties of a group Managed Service Account (gMSA). You can assign this role to all assistant administrators who are responsible for managing a gMSA.

Manage and Execute Custom Tools

Provides all the powers required to create, manage, and execute custom tools. Assign this role to assistant administrators responsible for managing custom tools.

Manage Clone Exceptions

Provides all the powers required to create and manage clone exceptions.

Manage Policies and Automation Triggers

Provides all the powers required to define policies and automation triggers. Assign this role to assistant administrators responsible for maintaining company policies and automating workflows.

Manage Security Model

Provides all the powers required to define the Administration rules, including ActiveViews, assistant administrators, and roles. Assign this role to assistant administrators responsible for implementing and maintaining your security model.

Manage Virtual Attributes

Provides all the powers required to create and manage virtual attributes. Assign this role to assistant administrators responsible for managing virtual attributes.

OU Administration

Provides all the powers required to manage organizational units. Assign this role to assistant administrators responsible for managing the Active Directory structure.

Public Folder Administration

Provides the powers to create, modify, delete, enable, or disable mail and view the properties of your Public Folder. You can assign this role to all assistant administrators who are responsible for managing Public Folder.

Replicate Files

Provides all the powers required to upload, delete, and modify file information. Assign this role to assistant administrators responsible for replicating files from the primary Administration server to other Administration servers in the MMS and the DRA client computers.

Reset Local Administrator Password

Provides all the powers to reset the local administrator account password and view the name of the computer administrator. Assign this role to assistant administrators responsible for managing the administrator accounts.

Self Administration

Provides all the powers required to modify basic properties, such as telephone numbers, of your own user account. Assign this role to assistant administrators to allow them to manage their own personal information.

8.1.3 Advanced Query Management

Execute Advanced Queries

Provides all the powers required to execute saved advanced queries. Assign this role to assistant administrators responsible for executing advanced queries.

Manage Advanced Queries

Provides all the powers required to create, manage, and execute advanced queries. Assign this role to assistant administrators responsible for managing advanced queries.

8.1.4 Audit Management

Audit All Objects

Provides all the powers required to view properties of objects, policies, and configurations across your enterprise. This role does not allow an assistant administrator to modify properties. Assign this role to assistant administrators responsible for auditing actions across your enterprise. Allows assistant administrators to view all nodes except the Custom Tools node.

Audit Limited Account and Resource Properties

Provides powers for all object properties.

Audit Resources

Provides all the powers required to view properties of managed resources. Assign this role to assistant administrators responsible for auditing resource objects.

Audit Users and Groups

Provides all the powers needed to view user account and group properties, but no powers to modify these properties. Assign this role to assistant administrators responsible for auditing account properties.

8.1.5 Computer Management

Computer Administration

Provides all the powers required to modify computer properties. This role allows assistant administrators to add, delete, and shut down computers, as well as synchronize domain controllers. Assign this role to assistant administrators responsible for managing computers in the ActiveView.

Create and Delete Computer Accounts

Provides all the powers required to create and delete a computer account. Assign this role to assistant administrators responsible for managing computers.

Manage Computer Properties

Provides all the powers required to manage all properties for a computer account. Assign this role to assistant administrators responsible for managing computers.

View All Computer Properties

Provides all the powers required to view properties of a computer account. Assign this role to assistant administrators responsible for auditing computers.

8.1.6 Exchange Management

Clone User with Mailbox

Provides all the powers required to clone an existing user account along with the account mailbox. Assign this role to assistant administrators responsible for managing user accounts.

NOTE:To allow the assistant administrator to add the new user account to a group during the clone task, also assign the Manage Group Memberships role.

Create and Delete Resource Mailbox

Provides all the powers required to create and delete a mailbox. Assign this role to assistant administrators responsible for managing mailboxes.

Mailbox Administration

Provides all the powers required to manage Microsoft Exchange mailbox properties. If you use Microsoft Exchange, assign this role to assistant administrators responsible for managing Microsoft Exchange mailboxes.

Manage Exchange Mailbox Rights

Provides all the powers required to manage security and rights for Microsoft Exchange mailboxes. If you use Microsoft Exchange, assign this role to assistant administrators responsible for managing Microsoft Exchange mailbox permissions.

Manage Group Email

Provides all the powers required to view, enable, or disable the email address for a group. Assign this role to assistant administrators responsible for managing groups or email addresses for account objects.

Manage Mailbox Move Requests

Provides all the powers required to manage mailbox move requests.

Manage Resource Mailbox Properties

Provides all the powers required to manage all properties for a mailbox. Assign this role to assistant administrators responsible for managing mailboxes.

Manage User Email

Provides all the powers required to view, enable, or disable the email address for a user account. Assign this role to assistant administrators responsible for managing user accounts or email addresses for account objects.

Reset Unified Messaging PIN Properties

Provides all the powers required to reset Unified Messaging PIN properties for user accounts.

Resource Mailbox Administration

Provides all the powers required to manage resource mailboxes.

Shared Mailbox Administration

Provides all the powers required to create, modify, delete, and view the properties of your shared mailboxes. Assign this role to all assistant administrators responsible for managing shared mailboxes.

View All Resource Mailbox Properties

Provides all the powers required to view properties for a resource mailbox. Assign this role to assistant administrators responsible for auditing resource mailboxes.

8.1.7 Group Management

Create and Delete Groups

Provides all the powers required to create and delete a group. Assign this role to assistant administrators responsible for managing groups.

Dynamic Group Administration

Provides all the powers required to manage Active Directory dynamic groups.

Group Administration

Provides all the powers required to manage groups and group memberships, and view corresponding user properties. Assign this role to assistant administrators responsible for managing groups or account and resource objects that are managed through groups.

Manage Dynamic Distribution Groups

Provides all the powers required to manage Microsoft Exchange dynamic distribution groups.

Manage Group Membership Security

Provides all the powers required to designate who can view and modify Microsoft Windows group memberships through Microsoft Outlook

Manage Group Memberships

Provides all the powers required to add and remove user accounts or groups from an existing group, and view the primary group of a user or computer account. Assign this role to assistant administrators responsible for managing groups or user accounts.

Manage Group Properties

Provides all the powers required to manage all properties for a group. Assign this role to assistant administrators responsible for managing groups.

Manage Temporary Group Assignments

Provides all the powers required to create and manage temporary group assignments. Assign this role to assistant administrators responsible for managing groups.

Rename Group and Modify Description

Provides all the powers required to modify the name and description of a group. Assign this role to assistant administrators responsible for managing groups.

View All Group Properties

Provides all the powers required to view properties for a group. Assign this role to assistant administrators responsible for auditing groups.

8.1.8 Reporting Management

Manage Active Directory Collectors, DRA Collectors, and Management Reporting Collectors

Provides all the powers required to manage Active Directory Collectors, DRA Collectors, and Management Reporting Collectors for data collection. Assign this role to assistant administrators responsible for managing reporting configuration.

Manage Active Directory Collectors, DRA Collectors, Management Reporting Collectors, and Database Configuration

Provides all the powers required to manage Active Directory Collectors, DRA Collectors, Management Reporting Collectors, and database configuration for data collection. Assign this role to assistant administrators responsible for managing reporting and database configuration.

Manage UI Reporting

Provides all the powers required to generate and export Activity Detail reports for users, groups, contacts, computers, organizational units, powers, roles, ActiveViews, containers, published printers, and assistant administrators. Assign this role to assistant administrators responsible for generating reports.

Manage Database Configuration

Provides all the powers required to manage database configuration for Management reports. Assign this role to assistant administrators responsible for managing reporting database configuration.

View Active Directory Collectors, DRA Collectors, Management Reporting Collectors, and Database Configuration Information

Provides all the powers required to view AD collectors, DRA collectors, management reporting collectors, and database configuration information.

8.1.9 Resource Management

Create and Delete Resources

Provides all the powers required to create and delete shares and computer accounts, and clear event logs. Assign this role to assistant administrators responsible for managing resource objects and event logs.

Manage Printers and Print Jobs

Provides all the powers required to manage printers, print queues, and print jobs. To manage print jobs associated with a user account, the print job and the user account must be included in the same ActiveView. Assign this role to assistant administrators responsible for maintaining printers and managing print jobs.

Manage Resources for Managed Users

Provides all the powers required to manage resources associated with specific user accounts. The assistant administrator and the user accounts must be included in the same ActiveView. Assign this role to assistant administrators responsible for managing resource objects.

Manage Services

Provides all the powers required to manage services. Assign this role to assistant administrators responsible for managing services.

Manage Shared Folders

Provides all the powers required to manage shared folders. Assign this role to assistant administrators responsible for managing shared folders.

Resource Administration

Provides all the powers required to modify properties of managed resources, including resources associated with any user account. Assign this role to assistant administrators responsible for managing resource objects.

Start and Stop Resources

Provides all the powers required to pause, start, resume, or stop a service, start or stop a device or printer, shut down a computer, or synchronize your domain controllers. Also provides all the powers required to pause, resume, and start services, stop devices or print queues, and shut down computers. Assign this role to assistant administrators responsible for managing resource objects.

8.1.10 Server Management

Built-in Scheduler - Internal Use Only

Provides powers to schedule when DRA refreshes the cache.

Application Servers Administration

Provides the powers required to configure, view, and delete application server configurations.

Configure Servers and Domains

Provides all the powers required to modify Administration server options and managed domains. Also provides powers necessary to configure and manage Azure tenants. Assign this role to assistant administrators responsible for monitoring and maintaining the Administration servers and managing Azure tenants.

Unified Change History Server Administration

Provides the powers required to configure, view, and delete Unified Change History server configurations.

Workflow Automation Server Administration

Provides the powers required to configure, view, and delete Workflow Automation server configurations.

8.1.11 User Account Management

Create and Delete User Accounts

Provides all the powers required to create and delete a user account. Assign this role to assistant administrators responsible for managing user accounts.

Help Desk Administration

Provides all the powers required to view user account properties, and to change passwords and password-related properties. This role also allows assistant administrators to disable, enable, and unlock user accounts. Assign this role to assistant administrators responsible for Help Desk duties associated with ensuring users have proper access to their accounts.

Manage User Dial in Properties

Provides all the powers required to modify the dial in properties of user accounts. Assign this role to assistant administrators responsible for managing user accounts that have remote access to the enterprise.

Manage User Password and Unlock Account

Provides all the powers required to reset the password, specify password settings, and unlock a user account. Assign this role to assistant administrators responsible for maintaining user account access.

Manage User Properties

Provides all the powers required to manage all properties for a user account, including Microsoft Exchange mailbox properties. Assign this role to assistant administrators responsible for managing user accounts.

Rename User and Modify Description

Provides all the powers required to modify the name and description of a user account. Assign this role to assistant administrators responsible for managing user accounts.

Reset Password

Provides all the powers required to reset and modify passwords. Assign this role to assistant administrators responsible for password management.

Reset Password and Unlock Account Using SPA

Provides all the powers required to use Secure Password Administrator to reset passwords and unlock user accounts.

Transform a User

Provides all the powers required to add a user to or remove a user from groups found in a template account, including the ability to modify the user's properties while transforming the user.

User Administration

Provides all the powers required to manage user accounts, associated Microsoft Exchange mailboxes, and group memberships. Assign this role to assistant administrators responsible for managing user accounts.

View All User Properties

Provides all the powers required to view properties for a user account. Assign this role to assistant administrators responsible for auditing user accounts.

8.1.12 WTS Administration

Manage WTS Environment Properties

Provides all the powers required to change the WTS environment properties for a user account. Assign this role to assistant administrators responsible for maintaining the WTS environment or managing user accounts.

Manage WTS Remote Control Properties

Provides all the powers required to change the WTS remote control properties for a user account. Assign this role to assistant administrators responsible for maintaining WTS access or managing user accounts.

Manage WTS Session Properties

Provides all the powers required to change the WTS session properties for a user account. Assign this role to assistant administrators responsible for maintaining WTS sessions or managing user accounts.

Manage WTS Terminal Properties

Provides all the powers required to change the WTS terminal properties for a user account. Assign this role to assistant administrators responsible for maintaining WTS terminal properties or managing user accounts.

WTS Administration

Provides all the powers required to manage Windows Terminal Server (WTS) properties for user accounts in the ActiveView. If you use WTS, assign this role to assistant administrators responsible for maintaining the WTS properties of user accounts.