Jump to content

Recommended Posts

Posted

Hi all,

 

For those using Locker for AD automation, can I ask what level of permissions you have assigned to the Locker AD account?

 

We are currently reviewing privileged accounts and trying to reduce standing Domain Admin membership where possible. As part of that, I asked Locker support whether their account could run with delegated permissions rather than Domain Admin.

Their response was that, in their experience, Domain Admin is required for reliable operation, particularly because many school environments have inherited or explicit permissions on OUs, users and folders which can cause delegated models to fail in inconsistent ways.

 

That explanation does make sense, especially in older AD environments, but I’d be interested to hear what others are doing in practice.

 

Are you running the Locker account as:

  • Domain Admin
  • A delegated account with specific OU permissions
  • Something else entirely

 

If you are using delegated permissions successfully, I’d be interested to know roughly what permissions you’ve assigned and whether there are any Locker functions that don’t work as expected.

I’m not looking to criticise Locker here — just trying to understand what is realistic and what other schools have settled on from a security/practicality point of view.

 

Thanks for taking the time to read, and reply.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...