(imported topic written by murtasma91)
We have an operator who is unable to manage any workstations in their site.
Delegation Configuration
-
We have a site that all computers are automatically subscribed to. Inside this site there is an automatic gorup, the group looks for a special file on the workstation (a custom property we created) and the active directory path.
-
An action is setup that runs against all workstations that are members of the group above and subscribes the workstation to another custom site (Navy).
-
Inside the Navy site there is a duplicate of the automatic computer gorup in #1. This group is then used on the operator account to control delegation.
We have over 40 sites in our envrioment that are configured very similar but with different groups and sites. This process has seemed to work well for Console Operator delegation.
When I view the 2 automatic groups (One in the Master Operator Site and one in the Navy site the members of each group are identical which is expected). The console operator account that is unable to manage these workstation in the Navy Site Automatic group group has read/write premissions to the Navy site. I double checked the delegation rights for the Console Operator and it’s using the correct scope gorup Navy:Navy Scope Group. However when viewing the tab that shows what computers he is able to manage none show up.
The groups appear to be correctly populated, the operator has rights to the site, the correct site is selected for delegation on the operator account.