-
site security
-
security principal (object to which to assign permissions
- user
- group
- permissions and permission levels
- securable objects
-
default groups
- visitors: read permission level
- members: contribute permission level
- owners: full control
-
site templates add groups
- viewers
- approvers: approve new and changed content
- designers: alter page design in browser and sp designer
- hierarchy managers: create folders, lists, libraries
- restricted readers
- style resource readers: read only master pages and style library
-
custom groups
-
when
- when more user roles than you can model with default groups
- when you want to use different names than default groups: rename
- when you want to import ad groups and keep name etc
-
hierarchical membership management
- it admin creates group project managers
- 2nd group project members, owned by project managers
- project managers can grant access, permissions to users without involvement of it admin
-
group management comparison
-
using ADDS groups without SP groups
- adds in classic or claimsbased mode
- grant permissions from sp directly to add groups
-
Sharepoint groups
- place ad users directly in sp groups
-
nesting ad groups in sp groups
-
advantages
- adds admin remains in control of group membership and structure
- sp admin remain in control of sp resources
- adds membership changes are automatically reflected in sp
-
disadvantages
- sp admin cannot see the individual members of a group
- sites to which you grant group access do not appear automatically in mysites
- problems with deep nesting ad groups
-
administrative groups
-
site collection administrators
- full control over site collection
-
sharepoint farm administrators
- recommended is adding a group to farm administators
- are responsible for the config of the farm as a whole
- access to all settings in ca
-
have no access to site collections by default
- can take ownership
-
windows administrators
- members of local admin group on sp server
- can perform all the actions of a sp farm admin
- can deploy web parts to global assembly cache (gac)
- can create websites, web apps, and control iis settings
- can stop and start services
- can runs stsadm.exe command
-
user information list
- details of current users and activities
- dynamic
- differs form people and groups list
-
accounts are added when
- their user account is granted access individually
- they contribute to the site
- they set up an alerts
- http://spserver/sitecollection/_catalogs/users/simple.aspx