Chat now with support
Chat with Support

Active Administrator 8.4 - Installation Guide

Installation Considerations for Active Administrator Installing and configuring Active Administrator

DC Management

For all Active Administrator® modules to operate properly, the Active Administrator Foundation service (AFS) requires an account that is a member of the Domain Admins group. However, you may want to customize access to each module for console users or the AFS account. The following table lists the specific permission requirements for the DC Management module.

NOTE: To assign roles in Active Administrator, select Configuration | Role Based Access | New. See Defining role-based access in the Quest® Active Administrator® User Guide for detailed information.

DC Management Landing Page

Must have the Active Administrator Domain Controller Management role.

Must have read access to the selected domain controller.

N/A

DC Status

Must have the Active Administrator Domain Controller Management role.

Must have read access to the selected domain controller, have WMI remote access enabled, and must be a member of the Distributed COM users group.

N/A

DC Services

Must have the Active Administrator Domain Controller Management role.

Must have full control on the selected domain controller.

N/A

DC Performance

Must have the Active Administrator Domain Controller Management role.

Must have read access to the selected domain controller and be a member of the Performance Log Users group.

N/A

DC Event Logs

Must have the Active Administrator Domain Controller Management role.

Must have read access to the selected event log on the selected domain controller.

N/A

DNS Management

For all Active Administrator® modules to operate properly, the Active Administrator Foundation service (AFS) requires an account that is a member of the Domain Admins group. However, you may want to customize access to each module for console users or the AFS account. The following table lists the specific permission requirements for the DNS Management module.

NOTE: To assign roles in Active Administrator, select Configuration | Role Based Access | New. See Defining role-based access in the Quest® Active Administrator® User Guide for detailed information.

DNS Landing Page

Must have the Active Administrator DNS Management role.

Must have full control on the selected DNS server

Must be a member of the AA_Users group.

DNS Management

Must have the Active Administrator DNS Management role.

To view, create, edit, or delete DNS records, must have full control on the selected DNS server.

N/A

DNS Monitoring

Must have the Active Administrator DNS Management role.

Must be a member of the AA_Users group.

DNS Analyzer

Must have the Active Administrator DNS Management role.

N/A

DNS Event Log

Must have the Active Administrator DNS Management role.

Must have read access to the DNS event log on the selected DNS server.

N/A

DNS Search

Must have the Active Administrator DNS Management role.

Must have full control access on the selected DNS servers.

N/A

Active Administrator Module Configuration

For all Active Administrator® modules to operate properly, the Active Administrator Foundation service (AFS) requires an account that is a member of the Domain Admins group. However, you may want to customize access to each module for console users or the AFS account. The following table lists the specific permission requirements for the Configuration module

NOTE: To assign roles in Active Administrator, select Configuration | Role Based Access | New. See Defining role-based access in the Quest® Active Administrator® User Guide for detailed information.

Configuration Landing Page

Tasks

Role Based Access

SMTP Settings

Azure Configuration

Notification Settings

Active Template Settings

Agent Installation Settings

Recovery Settings

GPO History Settings

GPO History Settings

Certification Configuration

Service Monitoring Policy

Must have the Active Administrator Full Control role.

Must be a member of the AA_Users group.

Archive Databases

Must have the Active Administrator Full Control role.

Must have permission on the target database server to create databases.

User Logon Agent Settings

Must have the Active Administrator Full Control role.

Must be a member of the AA_Admins group.

Active Directory Health minimum permissions

For the Active Directory Health module to operate properly, the Active Administrator Foundation service (AFS) requires an account that is a member of the Domain Admins group. See Active Directory Health. You may want to customize access to each Active Directory Health subsystem for console users or the AFS account. This section details the minimum permission requirements for the Active Directory Health module and its subsystems.

Topics:

Related Documents