Next Topic

Previous Topic

Book Contents

User Policies

The Groups / Users Policies tab sets KDS policies for (user) groups for a selected domain.

Once a probe is installed, KDS is configured by setting selected domain folders and items to included or excluded. KDS policies provide IT automation—such as installing agents or creating users—only for included folders and items. KDS only harvests detailed information for included folders and items, minimizing the amount of data required to maintain synchronization with the domain.

For more information see:

Header Fields

  • User Policies Status

Word 80% / HTML 100% - Original - KDS policies have not yet been configured.

Word 80% / HTML 100% - Modified - KDS policies have been configured but not yet applied. After clicking the Apply Changes button, this icon remains unchanged until the harvest has been completed.

Word 80% / HTML 100% - Applied - KDS policies have been applied.

  • Last Full Sync - Date/time of last full synchronization for this domain.
  • Last Incremental Sync - Date/time of last incremental synchronization of all outstanding changes for this domain.

Actions

  • Do not include Users - Excludes all users in a selected group.
  • Configure Users Policy - Includes selected users as either VSA users or Portal Access candidates.
    • Do Not Include Users - Do not create VSA user logons or Portal Access logons for domain users listed in this user group.
    • Create Staff Members - Creates a staff member record. These users can be assigned Portal Access to a machine manually.
    • Note: The user can only be manually assigned the portal access user of a machine—using the Users & Portal Users page—if the user was the last user logged on to that machine. The list of eligible machines are listed in the Last Logged-onto Machines field in the lower panel of this same page.
    • Create Staff and make Auto Portal Candidates - Designates domain users in this user group as Portal Access candidates. See Making Portal Access Candidates for details.
    • Create VSA Users - Creates VSA user logons for domain users listed in this user group.
      • Role Lookup
      • Scope Lookup
    • If a scope with the same name as the organization does not already exist, a Word 60% / HTML 100% displays to the right of the Scope Lookup drop-down list of the User Policy dialog. Clicking the Word 60% / HTML 100% icon enables you to create a new scope that has the same name as the organization associated with the domain. Once the scope is created the Word 60% / HTML 100% no longer displays to the right of the Scope Lookup drop-down list and text at the top of the dialog indicates the default scope already exists.
    • If the same user is assigned to multiple groups, and different roles and scopes are assigned to each group, then when the user logs on to the VSA, these roles and scopes will be available in the roles/scope selector in the upper-right corner of the VSA window.

      Note: Roles/scope assignments using User Policies can be modified and reapplied multiple times. Successive changes will cause roles and scopes to accumulate, rather than be replaced. KDS never removes records in the VSA.

  • Apply Changes - Applies KDS policies changes for both the Computer / Contact Policies tab and the User Policies tab.

    Note: Do not Apply Changes until policies are set on both tabs.

  • Refresh - Refreshes this tab.

Column Headings

  • Type -
  • Group Name - A canonical name provides the complete hierarchy of OUs/containers used to locate folders and items—such as computers, contacts or groups—in a domain, similar in format to the full path name of a file in a disk directory.
  • Users Policy
    • Do Not Include Users - Do not create VSA user logons or Portal Access logons for domain users listed in this user group.
    • Create Staff Members -
    • Create Staff and make Auto Portal Candidates - Designates domain users in this user group as Portal Access candidates. See Making Portal Access Candidates for details.
    • Create VSA Users - Creates VSA user logons for domain users listed in this user group.
  • Role Policy - The VSA role to assign to newly created VSA users if Users Policy is Create VSA Users. Role policy can also be set to.
    • Use existing Role
    • Do not create Role
  • Scope Policy - The VSA scope to assign to newly created VSA users if Users Policy is Create VSA Users. Scope policy can also be set to.
    • Use existing Scope
    • Do not create Scope