...
In the Edit roles dialog select the AD group name from the drop down, which is to be mapped to the DVI5 role. Members of the AD group will, if added as users, automatically be granted the permissions of the DVI5 role.
Click OK.
Repeat for all the AD groups:
Warning |
---|
Note that only one AD-group can be assigned to each role. |
Adding users
Click on the Users button on the Administration tab:
...
On the left is a list box with all members of the selected group. Choose a user and click on
Warning |
---|
If a user If you add a user that is a member of more than one of the legal AD-groups, it will have unpredictable consequences. That is why the The following message appears: You will still be able to add the user, but it is not adviceable to do so. |
Aftrer choosing a "legal" user, you get this message:
The SysAdmin will always be able to add users, and the Administrator role will typically be able to do it as well.
If you add users as SysAdmin, you must also assign the user to an agency, whereas as an Administrator, the users agency will automatically be that of the Administrator.
In this case it is the SysAdmin adding users, and an agency for the user should be selected, and Is approved should be checked to give the user access:
To finish click on the Save data button:
In the column DVI Roles you can see which role the user is assigned to. This reflects the users membership in the Active Directory group, and can not be altered for the individual user.
Locking out a user
You can uncheck the Is approved column to temporarily lock a user out from the system.