The permissions available to each user are split into sections:
Computer Information Permissions
Icon
Permission
Description
Read Computer Information
Allows the user to bring up the Computer Information window for computers in this container. Computer Information includes common attributes from Active Directory, such as Operating System information.
Write Computer Information
(Requires the Read Computer Information permission) This allows the user to edit the description of the computer from the Computer Information window. This requires OVERLAPS to have write permission to the Description property.
Allows the user to run a Group Policy Update Computer Management Tool on the selected computers in this container.
Ping Computer
Permits the user to run an ICMP Ping on any computers selected in this container.
Restart Computer
Permits the user to remotely restart any computers in this container.
Shutdown Computer
Permits the user to remotely shutdown computers in this container.
Read Password Permissions
Icon
Permission
Description
Read Passwords
With this option checked, the user/group can read the password of any computer in this Organizational Unit.
Read Passwords with Authorisation
Alternatively, checking this option will allow the user/group to read the password of any computer in this Organizational Unit, but they will need to submit an Authorisation Request first which must be authorised by one or more nominated Authorisers.
Read Passwords with Justificaton
This option acts much like the “Read Passwords with Authorisation” setting, but instead of going through an entire authorisation process, the user must simply provide some information about why they needed access to the password, which is recorded in the History Log.
Reset/Expire Password Permissions
Icon
Permission
Description
Expire Passwords
With this option checked, the user/group can expire the password of any computer in this Organizational Unit. This will trigger the computer to reset its password when it next runs a Group Policy update.
Expire Passwords with Authorisation
As with the Read Password permissions, this also allows users to expire passwords, but will require them to submit an Authorisation Request first.
Authorisation Request Authoriser Permissions
Icon
Permission
Description
Authoriser for Normal User Requests
Checking this option nominates this user/group as an Authoriser for normal user requests. When a user who requires authorisation attempts to perform a relevant action, these users will be notified by email and must login to OVERLAPS to authorise the action. In order to have users who require authorisation to read or expire passwords, the container must also have at least one Authoriser.
Authorise Self-Service Requests
As with the regular Authoriser permissions, except this user has permission to authorise Self-Service users to read computer passwords.
Rules for Permissions
There are a few rules to consider when settings permissions on a container:
Users can either have “Read” permission or “Read with Authorisation” permission, you cannot check both.
Users cannot have both “Read with Authorisation” and “Read with Justification” permissions.
Similarly, users can only have “Expire” or “Expire with Authorisation” permissions.
In order to add users who require authorisation, the container must have at least one nominated Authoriser user.