Создание Роли ApplicationImpersonation для внешние синхронизации
Get-ManagementRoleAssignment -RoleAssignee PMSyncService -Delegating $false | Format-Table -Auto Name,Role,RoleAssigneeName,RoleAssigneeType,CustomRecipientWriteScope
Удаление
Get-ManagementRoleAssignment | Where {$_.Role -eq “ApplicationImpersonation” -and $_.RoleAssigneeName -eq “Your_User_Account“} | Remove-ManagementRoleAssignment
Get-ManagementRoleAssignment | Where {$_.Role -eq “ApplicationImpersonation” -and $_.RoleAssigneeName -eq “Your_User_Account“} | Remove-ManagementRoleAssignment
$DL_ktalk_fbk-corp_GROUPDN = $(Get-Group "DL_ktalk_fbk-corp_USERS").Identity.DistinguishedName
New-ManagementScope -Name "PMImpScope" –RecipientRestrictionFilter "MemberOfGroup -contains '$PMUsersDN'"
New-ManagementRoleAssignment –Name:PMImpMgmtRole –Role:ApplicationImpersonation –User:PMSyncService –CustomRecipientWriteScope:PMImpScope
Get-ManagementRoleAssignment -RoleAssignee PMSyncService -Delegating $false | Format-Table -Auto Name,Role,RoleAssigneeName,RoleAssigneeType,CustomRecipientWriteScope
Get-ManagementRoleAssignment -RoleAssignee PMSyncService -Delegating $false | Format-Table -Auto Name,CustomRecipientWriteScope,Role
New-ManagementScope -Name "PMImpScope" –RecipientRestrictionFilter "MemberOfGroup -contains '$PMUsersDN'"
New-ManagementRoleAssignment –Name:PMImpMgmtRole –Role:ApplicationImpersonation –User:PMSyncService –CustomRecipientWriteScope:PMImpScope
Get-ManagementRoleAssignment -RoleAssignee PMSyncService -Delegating $false | Format-Table -Auto Name,Role,RoleAssigneeName,RoleAssigneeType,CustomRecipientWriteScope
Get-ManagementRoleAssignment -RoleAssignee PMSyncService -Delegating $false | Format-Table -Auto Name,CustomRecipientWriteScope,Role
Комментарии
Отправить комментарий