SCCM Collection Security
Hi All
This might be a dumb question.
I have a multi site hierarchy I do all my collection creation at the top level site and set the security permissions on this collection.
The collection flows down but the security doesn't, Is this correct ? Or do I have to go to each Site Server and set the security again at that collection or do I have an issue with my SCCM sites ?
The SCCM version is SP1 R2.
Many Thanks
Neil
November 6th, 2008 12:50pm
No not a dumb question.The behaviour you are seeing is normal. Collections propogate down a site heirarchy. Security rights don't. Retarded isn't it!So yes, you do have to go to each Site Server and set security again. Having said that, think about whether you really need to do this. Are you (or your SCCM administrators) doing configuration work on multiple site servers? There are instances where this does make sense. It all depends on your specific environment.Cheers.Blah Blah Blah
Free Windows Admin Tool Kit Click here and download it now
December 19th, 2008 5:11am
Collections at child sites automaticallyget locked so you can't edit them anyway. So whythere's a need to set security rights on them?
December 19th, 2008 12:10pm
What if I want to allow administrators of the Child Primary the ability to create collections underneath the locked collection?
Free Windows Admin Tool Kit Click here and download it now
January 19th, 2011 10:53am
Does not work using the console, but what's the requirement behind that? It *might* be possible using the SDK.
January 19th, 2011 11:17am
We have a Central server where we do global administration. So there are standard packages, collections that everyone should see. However, then at each of the Primaries in the regions, each team looks after their own clients. But (BIG but) there are departments
within those regions. So for example Department A & B. They both need access to the same Primary site, but not access to the other Primaries in the hierarchy. They then need access to only their own departmental clients within their Site. It's a pretty
complex setup. (Would've been better to get vNext in, but the decision was made that it would only go in later.) They then need to be able to create objects in SCCM that only their department can access. Make sense?
Free Windows Admin Tool Kit Click here and download it now
January 20th, 2011 2:59am
Makes sense, but why do they have to create subcollections under the locked ones on the primary child? You can create new collections at the top level. Isn't that not enough (given that you set up appropriate security rights)?
January 20th, 2011 3:34am


