Basic settings

Determine the basic settings for Group Wizard, comfort feature and sandbox.

 

Use the Group Wizard

The Group Wizard is one of the most powerful features of ARM.

 

Option disabled

File server access rights changes made with ARM are written directly into the ACL (Access Control List). If you do this with users and not with groups, this procedure contradicts Microsoft's recommended best practices.

 

Option enabled

ARM automatically creates and removes permission groups (ARM groups). Users and groups are then assigned memberships in these ARM groups.

 

Use the simulation mode

Activate the simulation mode to preview all planned changes, for example, which groups would be created. You can not apply changes in this mode.

If you want to execute changes with ARM, the simulation mode must be deactivated.

 

Use the comfort feature

When users register on the network, their group memberships are verified and added to the Kerberos token. When assigning permissions with the Group Wizard via group memberships, they only become active after the user logs out of and into the system again.

By activating the "comfort feature", users temporarily receive direct access rights. These are active immediately and are automatically removed after a configurable time. This allows the user to access required resources immediately without having to log out and in again.

ARM does not set temporary list permissions.  Users may not be able to navigate to the folders.

 

Activate or deactivate an initial test

Option enabled

The Group Wizard will determine all required steps for access rights changes in the ARM application immediately after clicking on "Apply".

 

Option disabled

Before determining the required changes, a dialog box will open, allowing you to make changes to Group Wizard options.

This can save a lot of time, especially if you want to perform complex access rights changes with non-standard Group Wizard options.