Universal Policy Administrator provides the following roles and permissions for one or more given platforms:
Table 5-1 Universal Policy Administrator Roles and Permissions
|
Role |
Platform |
Permissions |
|---|---|---|
|
Universal Policy Administrator Admins |
All Platforms |
Is the top level administrator with permissions to do everything with the system. |
|
Windows Admin |
Windows |
Is the top level administrator with permission to do everything with Windows group policies. |
|
Windows Approver |
Windows |
Has permission to approve, reject, or unapprove GPOs for export from the Universal Policy Repository to Active Directory. This role also has permissions to approve or unapprove ADMX files for export from the Universal Policy Repository to the central store. |
|
Windows Auditor |
Windows |
Has permission to audit, GPOs exported from the Universal Policy Repository to Active Directory and ADMX files from the Universal Policy Repository to the central store. |
|
Windows Editor |
Windows |
Has permission to send for approval and modify GPOs in the Universal Policy Repository and add ADMX files. |
|
Windows Importer |
Windows |
Has permission to import GPOs from Active Directory into the Universal Policy Repository and synchronize ADMX files from the central store. |
|
Windows Exporter |
Windows |
Has permission to export, GPOs from the Universal Policy Repository to Active Directory and ADMX files to the central store. |
|
Mac Admin |
Mac |
Is the top level administrator with permission to do everything with Mac policies. |
|
Mac Approver |
Mac |
Has permission to approve, reject, or unapprove Mac policy objects for export from the Universal Policy Repository to Active Directory. |
|
Mac Auditor |
Mac |
Has permission to audit, Mac policy objects exported from the Universal Policy Repository to Active Directory. |
|
Mac Editor |
Mac |
Has permission to send for approval and modify Mac policy objects in the Universal Policy Repository. |
|
Mac Importer |
Mac |
Has permission to import Mac policy objects from Active Directory into the Universal Policy Repository. |
|
Mac Exporter |
Mac |
Has permission to export, Mac policy objects from the Universal Policy Repository to Active Directory. |
|
Mac Importer |
Has permission to import Mac policy objects from Active Directory into the Universal Policy Repository. |
|
|
Mac Exporter |
Mac |
Has permission to export, Mac policy objects from the Universal Policy Repository to Active Directory. |
|
Linux Admin |
Linux |
Is the top level administrator with permission to do everything with Linux policies. |
|
Linux Approver |
Linux |
Has permission to approve, reject, or unapprove Linux policy objects for export from the Universal Policy Repository to Active Directory. |
|
Linux Auditor |
Linux |
Has permission to audit, Linux policy objects exported from the Universal Policy Repository to Active Directory. |
|
Linux Editor |
Linux |
Has permission to send for approval and modify Linux policy objects in the Universal Policy Repository. |
|
Linux Importer |
Linux |
Has permission to import Linux policy objects from Active Directory to the Universal Policy Repository. |
|
Linux Exporter |
Linux |
Has permission to export, Linux policy objects from the Universal Policy Repository to Active Directory. |
NOTE:If a user is assigned to multiple roles, each role is additive and permissions for the least restrictive role apply at any given time.