Previous Topic: Cumulative PermissionsNext Topic: Security Scenario - Software Delivery


DSM Tree Permissions

The following table shows the minimum access type required to take action on a folder or object in the DSM tree.

Object / Folder

Minimum Access Type

Actions Allowed on Object/Folder

DSM Root Object (enterprise or domain)

Read

Expand the object and view its permissions and properties.

Computers and Users (Folder)

Read

Write

 

Execute

Expand the folder.

Link any computer or user to this folder.

Seal the folder.

Computer Object

Write

Link the computer to any group and access the Job Calendar (attach or detach) of the computer object.

User Object

Write

Link the user to any group.

Distribution Permissions

Below some information is collected to clarify the access rights needed for an enterprise Administrator when sending distribution orders to a domain.

Class Permission

Description

Create class permission

This class permission is needed for object class Software when sending for example an order to register software. By default, the security group Distributions has Full Control as class permission for every SD object class.

Write permission

This permission is needed when sending for example an order to link an object into a folder.

Delete permission

This permission is needed when sending for example an order to unregister software or a computer group.

Read and Execute

These permissions are needed on the root object (own area) of the area, to which a distributed fetch item order is directed.