{"id":218,"date":"2026-04-01T09:25:59","date_gmt":"2026-04-01T08:25:59","guid":{"rendered":"https:\/\/overlaps.co.uk\/docs\/?page_id=218"},"modified":"2026-04-01T09:35:30","modified_gmt":"2026-04-01T08:35:30","slug":"individual-permissions","status":"publish","type":"page","link":"https:\/\/overlaps.co.uk\/docs\/overlaps-documentation\/configuration\/container-permissions\/individual-permissions\/","title":{"rendered":"Individual Permissions"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">The permissions available to each user are split into sections:<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"computer-information-permissions\">Computer Information Permissions<\/h3>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th>Icon<\/th><th>Permission<\/th><th>Description<\/th><\/tr><\/thead><tbody><tr><td><img loading=\"lazy\" decoding=\"async\" width=\"21\" height=\"23\" class=\"wp-image-220\" style=\"width: 21px;\" src=\"https:\/\/overlaps.co.uk\/docs\/wp-content\/uploads\/2026\/04\/config-permissions-info-read-computer-info.png\" alt=\"Read Computer Information\"><\/td><td>Read Computer Information<\/td><td>Allows the user to bring up the Computer Information window for computers in this container. Computer Information includes common attributes from Active Directory, such as Operating System information.<\/td><\/tr><tr><td><img loading=\"lazy\" decoding=\"async\" width=\"20\" height=\"23\" class=\"wp-image-221\" style=\"width: 20px;\" src=\"https:\/\/overlaps.co.uk\/docs\/wp-content\/uploads\/2026\/04\/config-permissions-info-write-computer-info.png\" alt=\"Write Computer Information\"><\/td><td>Write Computer Information<\/td><td>(Requires the Read Computer Information permission) This allows the user to edit the description of the computer from the Computer Information window. This requires OVERLAPS to have write permission to the Description property.<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"computer-management-tools\">Computer Management Tools<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">This list of permissions require Computer Management Tools to be enabled and configured (see <a href=\"https:\/\/overlaps.co.uk\/docs\/overlaps-documentation\/configuration\/settings\/computer-management\/\">Computer Management Settings<\/a> for information on enabling the tools, and <a href=\"https:\/\/overlaps.co.uk\/docs\/overlaps-documentation\/installation-and-configuration\/active-directory\/#computer-management-tool-permissions\">Computer Management Tool Permissions<\/a> for information on the required permissions setup.)<\/p>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th>Icon<\/th><th>Permission<\/th><th>Description<\/th><\/tr><\/thead><tbody><tr><td><img loading=\"lazy\" decoding=\"async\" width=\"23\" height=\"23\" class=\"wp-image-223\" style=\"width: 23px;\" src=\"https:\/\/overlaps.co.uk\/docs\/wp-content\/uploads\/2026\/04\/config-permissions-cmt-gpupdate.png\" alt=\"Permission Icon for Trigger Group Policy Update\"><\/td><td>Trigger Group Policy Update<\/td><td>Allows the user to run a Group Policy Update Computer Management Tool on the selected computers in this container.<\/td><\/tr><tr><td><img loading=\"lazy\" decoding=\"async\" width=\"21\" height=\"21\" class=\"wp-image-224\" style=\"width: 21px;\" src=\"https:\/\/overlaps.co.uk\/docs\/wp-content\/uploads\/2026\/04\/config-permissions-cmt-ping.png\" alt=\"Permission Icon for Ping Computer\"><\/td><td>Ping Computer<\/td><td>Permits the user to run an ICMP Ping on any computers selected in this container.<\/td><\/tr><tr><td><img loading=\"lazy\" decoding=\"async\" width=\"19\" height=\"19\" class=\"wp-image-225\" style=\"width: 19px;\" src=\"https:\/\/overlaps.co.uk\/docs\/wp-content\/uploads\/2026\/04\/config-permissions-cmt-restart.jpg\" alt=\"Permission Icon for Restart Computer\"><\/td><td>Restart Computer<\/td><td>Permits the user to remotely restart any computers in this container.<\/td><\/tr><tr><td><img loading=\"lazy\" decoding=\"async\" width=\"22\" height=\"21\" class=\"wp-image-226\" style=\"width: 22px;\" src=\"https:\/\/overlaps.co.uk\/docs\/wp-content\/uploads\/2026\/04\/config-permissions-cmt-shutdown.jpg\" alt=\"Permission Icon for Shutdown Computer\"><\/td><td>Shutdown Computer<\/td><td>Permits the user to remotely shutdown computers in this container.<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"read-password-permissions\">Read Password Permissions<\/h3>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th>Icon<\/th><th>Permission<\/th><th>Description<\/th><\/tr><\/thead><tbody><tr><td><img loading=\"lazy\" decoding=\"async\" width=\"27\" height=\"19\" class=\"wp-image-227\" style=\"width: 27px;\" src=\"https:\/\/overlaps.co.uk\/docs\/wp-content\/uploads\/2026\/04\/config-permissions-password-read.png\" alt=\"Permission Icon for Read Passwords\"><\/td><td>Read Passwords<\/td><td>With this option checked, the user\/group can read the password of any computer in this Organizational Unit.<\/td><\/tr><tr><td><img loading=\"lazy\" decoding=\"async\" width=\"19\" height=\"34\" class=\"wp-image-228\" style=\"width: 19px;\" src=\"https:\/\/overlaps.co.uk\/docs\/wp-content\/uploads\/2026\/04\/config-permissions-password-read-with-auth.png\" alt=\"Permission Icon for Read Passwords with Authorisation\"><\/td><td>Read Passwords with Authorisation<\/td><td>Alternatively, checking this option will allow the user\/group to read the password of any computer in this Organizational Unit, but they will need to submit an Authorisation Request first which must be authorised by one or more nominated Authorisers.<\/td><\/tr><tr><td><img loading=\"lazy\" decoding=\"async\" width=\"18\" height=\"18\" class=\"wp-image-229\" style=\"width: 18px;\" src=\"https:\/\/overlaps.co.uk\/docs\/wp-content\/uploads\/2026\/04\/config-permissions-require-justification.jpg\" alt=\"Permission Icon for Read Passwords with Justificaton\"><\/td><td>Read Passwords with Justificaton<\/td><td>This option acts much like the &#8220;Read Passwords with Authorisation&#8221; setting, but instead of going through an entire authorisation process, the user must simply provide some information about why they needed access to the password, which is recorded in the History Log.<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"resetexpire-password-permissions\">Reset\/Expire Password Permissions<\/h3>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th>Icon<\/th><th>Permission<\/th><th>Description<\/th><\/tr><\/thead><tbody><tr><td><img loading=\"lazy\" decoding=\"async\" width=\"23\" height=\"25\" class=\"wp-image-230\" style=\"width: 23px;\" src=\"https:\/\/overlaps.co.uk\/docs\/wp-content\/uploads\/2026\/04\/config-permissions-password-reset.png\" alt=\"Permission Icon for Expire Passwords\"><\/td><td>Expire Passwords<\/td><td>With this option checked, the user\/group can expire the password of any computer in this Organizational Unit. This will trigger the computer to reset its password when it next runs a Group Policy update.<\/td><\/tr><tr><td><img loading=\"lazy\" decoding=\"async\" width=\"23\" height=\"37\" class=\"wp-image-231\" style=\"width: 23px;\" src=\"https:\/\/overlaps.co.uk\/docs\/wp-content\/uploads\/2026\/04\/config-permissions-password-reset-with-auth.png\" alt=\"Permission Icon for Expire Passwords with Authorisation\"><\/td><td>Expire Passwords with Authorisation<\/td><td>As with the Read Password permissions, this also allows users to expire passwords, but will require them to submit an Authorisation Request first.<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"authorisation-request-authoriser-permissions\">Authorisation Request Authoriser Permissions<\/h3>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th>Icon<\/th><th>Permission<\/th><th>Description<\/th><\/tr><\/thead><tbody><tr><td><img loading=\"lazy\" decoding=\"async\" width=\"24\" height=\"25\" class=\"wp-image-232\" style=\"width: 24px;\" src=\"https:\/\/overlaps.co.uk\/docs\/wp-content\/uploads\/2026\/04\/config-permissions-password-authorise.png\" alt=\"Permission Icon for Authoriser for Normal User Requests\"><\/td><td>Authoriser for Normal User Requests<\/td><td>Checking this option nominates this user\/group as an Authoriser for normal user requests. When a user who requires authorisation attempts to perform a relevant action, these users will be notified by email and must login to OVERLAPS to authorise the action. In order to have users who require authorisation to read or expire passwords, the container must also have at least one Authoriser.<\/td><\/tr><tr><td><img loading=\"lazy\" decoding=\"async\" width=\"28\" height=\"20\" class=\"wp-image-233\" style=\"width: 28px;\" src=\"https:\/\/overlaps.co.uk\/docs\/wp-content\/uploads\/2026\/04\/config-permissions-password-authorise-self-service.png\" alt=\"Permission Icon for Authorise Self-Service Requests\"><\/td><td>Authorise Self-Service Requests<\/td><td>As with the regular Authoriser permissions, except this user has permission to authorise Self-Service users to read computer passwords.<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"rules-for-permissions\">Rules for Permissions<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">There are a few rules to consider when settings permissions on a container:<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li>Users can either have &#8220;<strong>Read<\/strong>&#8221; permission or &#8220;<strong>Read with Authorisation<\/strong>&#8221; permission, you cannot check both.<\/li>\n\n\n\n<li>Users cannot have both &#8220;<strong>Read with Authorisation<\/strong>&#8221; and &#8220;<strong>Read with Justification<\/strong>&#8221; permissions.<\/li>\n\n\n\n<li>Similarly, users can only have &#8220;<strong>Expire<\/strong>&#8221; or &#8220;<strong>Expire with Authorisation<\/strong>&#8221; permissions.<\/li>\n\n\n\n<li>In order to add users who require authorisation, the container must have at least one nominated Authoriser user.<\/li>\n<\/ol>\n","protected":false},"excerpt":{"rendered":"<p>The permissions available to each user are split into sections: Computer Information Permissions Icon Permission Description Read Computer Information Allows the user to bring up the Computer Information window for computers in this container. Computer Information includes common attributes from Active Directory, such as Operating System information. Write Computer Information (Requires the Read Computer Information [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"parent":66,"menu_order":100,"comment_status":"closed","ping_status":"closed","template":"","meta":{"footnotes":""},"class_list":["post-218","page","type-page","status-publish","hentry"],"_links":{"self":[{"href":"https:\/\/overlaps.co.uk\/docs\/wp-json\/wp\/v2\/pages\/218","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/overlaps.co.uk\/docs\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/overlaps.co.uk\/docs\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/overlaps.co.uk\/docs\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/overlaps.co.uk\/docs\/wp-json\/wp\/v2\/comments?post=218"}],"version-history":[{"count":2,"href":"https:\/\/overlaps.co.uk\/docs\/wp-json\/wp\/v2\/pages\/218\/revisions"}],"predecessor-version":[{"id":234,"href":"https:\/\/overlaps.co.uk\/docs\/wp-json\/wp\/v2\/pages\/218\/revisions\/234"}],"up":[{"embeddable":true,"href":"https:\/\/overlaps.co.uk\/docs\/wp-json\/wp\/v2\/pages\/66"}],"wp:attachment":[{"href":"https:\/\/overlaps.co.uk\/docs\/wp-json\/wp\/v2\/media?parent=218"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}