Skip to content

Temporary Administrators

strawgate edited this page Aug 31, 2016 · 2 revisions

Overview

The temporary administrator features of C3-Inventory allow the provisioning and automatic removal of administrative rights for end-users using actions or offers. The feature requires the following to be successful:

  1. Activation of Temporary Administrators Analysis
  2. Add Users to Administrators Group Temporarily
  3. Offer Temporary Administrative Rights
  4. Automatically remove expired administrative privileges

Activation of Temporary Administrators Analysis

The Analysis: Temporary Administrators - Windows should be activated to provide information on the current and previous temporary administrators on a machine.

This will provide two properties:

  1. Current administrators granted temporary rights
  2. Users previously granted temporary rights (and now expired)

Add users to Administrators Group Temporarily

The Fixlet: Invoke - Add Current User to Administrators Temporarily - Windows can be used to grant a user temporary administrative privileges.

This Fixlet has a number of actions available that determine the expiration date and time of the users administrative rights anywhere from 1 hour to 5 days.

Offer Temporary Administrative Privileges

By using the Fixlet: Invoke - Add Current User to Administrators Temporarily - Windows as an offer, you can temporarily grant users administrative rights in a self-service model.

Automatically remove expired administrative privileges

Use Fixlet: Invoke - Remove Expired Users from Temporary Administrators- Windows as a policy action to always remove expired users from the administrators group.

This should be actioned to run an unlimited number of times with no delay.