My question is this. The default global group "Domain Admin" has some sort of properties
associated with it that won't allow someone with account operator privelege alone to add
users to that group. If you create a new domain group, people with account operator
priveleges can add any user into that group. How can you you limit this access? Can one
get more granularity out of global groups? Is this a featur of a future release perhaps?
This lack of functionality gives rise to possible security problems with a resource
domain. If you create groups on the master that you use for administrative purposes
within the resource domain, users can be added to those groups. Is there no way to
restrict this privilege on a per group basis?
Thanks in advance.
-- Jay
ba...@ti.com