Setup
...
How To
Permissions Required
13 min
the folder manager module creates ad groups, sets permissions on folders using those groups, and manages the membership of the groups to do that the activate orchestrator (job) service, service account will need the following permissions on the folders, shares and ou(s) where groups that grant access to folders reside scan folder permissions grant to activate orchestrator service account see recommendation below grant on share rights read grant on target directory(ies) subfolders and files rights list folder contents create folders grant to activate orchestrator service account see recommendation below grant on share rights full control grant on parent directory(s) rights read, write and execute grant on on group ou and all descendant objects rights read write create all child objects delete all child objects secure folders grant to activate orchestrator service account see recommendation below grant on share rights full control grant on this folder, subfolders and files rights read, write and execute grant on group ou and all descendant objects rights read write create all child objects delete all child objects recommendation to grant these permissions it is recommended to create a group in an ou that only the activate orchestrator service account can write to assign rights listed above to the group create a service that adds users to the group ensure that a team with appropriate training to understand the access being requested are approvers for the service order the service for the orchestrator service account notes if possible, remove permissions for users other than the activate orchestrator service account to manage groups in the ou(s) where groups that control folder access reside