Quantcast
Channel: Forum Microsoft Identity Manager
Viewing all articles
Browse latest Browse all 4767

MPR design question - how to grant rights to only a given set of users to add other users to groups

$
0
0

Hi,

I have a scenario where I'm implementing a feature where users can request memership to owner approval groups. This is all good, no issues. However, another feature that is requested is that Assistants can request membership on behalf of other users too. 

This poses a bit of an MPR related challenge. The attribute in question is "ExplicitMember", and since every user should have the right to request group membership, I made an MPR which grants all users the right to request group membership (by being able to add to multivalued attribute "ExplicitMember"). However, this also means that every user can request membership on behalf of any other user too, and I need to restrict just this feature to be available for Assistants. I can create a set of Assistants but I'm not sure how the MPRs would look to allow this feature.

Any ideas?

Thanks


Viewing all articles
Browse latest Browse all 4767

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>