The Permission Management allows you to grant revoke permission on the files, folders and registry. Endpoint Central MSP Permission Management Configuration enables you to grant/revoke permissions to multiple computers from a central point.
Provide a name and description for the Permission Management configuration.
You can grant or revoke permissions for the following objects:
Files
To grant or revoke permissions for files, select the File tab and specify the following values:
Parameter
Description
User/Group Principal
Select the users and groups for whom you would like to grant or revoke permissions.
Action
Select the action from the following:
Append - To append to the existing file permissions. Please note that it will only append to the existing permissions on the object and will not overwrite. For example, for an object having full permissions, if you just select a deny permission to write, only write permission will be removed while the user/group can still modify the object.
Overwrite - To overwrite the existing file permissions
Revoke - To revoke the existing file permissions of the specified user/group. All the permissions to the specified user/group on that file will be removed. However, the inherited permissions will not be removed.
File name
Specify the name of the file for which you need to specify permissions.
Settings
Select the required options.
If you wish to add more permissions, click Add More Permissions button and repeat step 2. The values gets added to the List of Permission Actions table.
Folders
To grant or revoke permissions for folders, select the Folder tab and specify the following values:
Parameter
Description
User/Group Principal
Select the users and groups for whom you would like to grant or revoke permissions.
Action
Select the action from the following:
Append - To append to the existing folder permissions. Please note that it will only append to the existing permissions on the object and will not overwrite. For example, for an object having full permissions, if you just select a deny permission to write, only write permission will be removed while the user/group can still modify the object.
Overwrite - To overwrite the existing folder permissions
Revoke - To revoke the existing folder permissions. All the permissions to the specified user/group on that folder will be removed. However, the inherited permissions will not be removed.
Folder name
Specify the name of the folder for which you need to specify permissions.
Inheritance
Select the required option to specify how the permission should effect its subfolders and files
Settings
Select the required options.
If you wish to add more permissions, click Add More Permissions button and repeat step 2. The values gets added to the List of Permission Actions table.
Registry
To grant or revoke permissions for registry, select the Registry tab and specify the following values:
Parameter
Description
User/Group Principal
Select the users and groups for whom you would like to grant or revoke permissions.
Action
Select the action from the following:
- Append - To append to the existing registry permissions. Please note that it will only append to the existing permissions on the object and will not overwrite. For example, for an object having full permissions, if you just select a deny permission to write, only write permission will be removed while the user/group can still modify the object.
- Overwrite - To overwrite the existing registry permissions
- Revoke - To revoke the existing registry permissions. All the permissions to the specified user/group on that registry key will be removed. However, the inherited permissions will not be removed.
Hive
Select the registry hive from the given options
Key
Specify the key within that hive for which you need to set the permissions
Inheritance
Select the required options to specify how the permission should effect its subkeys.
Settings
Select the required options.
If you wish to add more permissions, click Add More Permissions button and repeat step 2. The values gets added to the List of Permission Actions table.
To modify a permission from the List of Permission Actions table, select the appropriate row and click icon and change the required values.
To delete a permission from the List of Permission Actions table, select the appropriate row and click icon.
Using the Defining Targets procedure, define the targets for deploying the Permission Management Configuration.
Click the Deploy button to deploy the defined Permission Management Configuration in the defined targets. The configuration will take effect during the next system startup.
To save the configuration as draft, click Save as Draft.