I have discovered that several of our active users are in our deny access group, although they seem to be able to authenticate against the server, open databases and read mail. My conclusion is that our deny access group doesn’t function as it should and this is, of course, a big security problem.
Does anyone know what could be the problem? I will be happy to answer any questions.
I don’t think adding people to a Deny Access group in itself will stop them using the server. The group name must be put into the server document(s) under the Security tab > “Not access server:” field.
You pointed right at the problem. The deny access group was not in the ‘Not access server’-field. I actually thought that this group would work without having to add it. Anyway this leads me to another question.
For some strange reason there are a number of active users in this group and I am afraid that they will not be able to work at all when adding the “deny access group” to the “not access server”-field. So what do I do? I could remove these active users from this group but I have heard that once you’re in the deny-group you can not be brought back, is this right? And furthermore, could there be any process or agent that put people in this group when some event occurs? I am trying to figure out how they were put there.
You can add and remove from this list as you wish. I’ve done it a number of times with people that have left and come back to the company. You just have to give the server time to pickup the changes before the user can once again access the server.
Also another note - this list has no affect for web based users.
In answer to your first query : all you need to do is remove the people from the group and they’re activated again. Simply edit the group document and delete their name! (Unless you have gone into their person document and done “Lockout ID” in their Check Password field etc.)
And about the process to put people in the group : If you go into Administrator and delete someone from the NAB you will be presented with a dialog box about what to do with their mailfile among other things. I’m pretty sure one of the options allows you to specify a group to put them into - which of course is supposed to be your deny access group. Or you can just put them into the deny access group if you just want to ban them.