Full Access Admin - not what it says it is?

Hi - I have given Full Access Admin rights to a group in the server config. A user in this group sets his access to Full Access Administrator in his Admin. client. He tries to add a group to the primary NAB and can’t. He gets the ‘You are not authorized’ popup. This user can manage the ACL for the NAB but cannot add a group unless he is specifically defined in the ACL with that role. Isn’t a Full Access Administrator supposed to have all privileges and roles enabled for every db regardless of the ACL settings?

Subject: Full Access Admin - not what it says it is?

You need to have the Administrator client open, then select Full Access Administration from the Administration menu with the desired server open. The access extends across clients, but you do need to deliberately invoke it from Administrator.

Subject: Full Access Admin - not what it says it is?

Nope… it just gives you access of sorts to open all the databases - regardless of the ACL. The functionality - Roles /Reader/Author fields are excluded from this feature.

I think that is a good thing. Allows a select few users to be able to open any database… but also give the opportunity to manage what they can do.

But, it is also a very dangerous feature as well.

Subject: RE: Full Access Admin - not what it says it is?

From the Admin help file:

Administrators who are designated as full access administrators in the Server document have manager access to all databases, with all privileges and roles enabled, on the server, regardless of whether they are listed in the database ACLs.

Subject: And it overides any ReaderNames field

From the help:Full access administrators

Full access administrator is the highest level of administrative access to the server. The full access administrator feature replaces the need to run a Notes client locally on a server. It resolves access control problems – for example, such as those caused when the only managers of a database ACL have left an organization.

Full access administrators have the following rights:

All the rights as listed for all administrator access levels (see above).

Manager access, with all roles and access privileges enabled, to all databases on the server, regardless of the database ACL settings.

Manager access, with all roles and access privileges enabled, to the Web Administrator database (WEBADMIN.NSF).

Access to all documents in all databases, regardless of Reader names fields.

The ability to create agents that run in unrestricted mode with full administration rights.

Access to any unencrypted data on the server.

Note Full access administrator does not allow access to encrypted data. The use of the specified user’s private key is required to decrypt documents that are encrypted with public keys. Similarly, a secret key is required to decrypt documents encrypted with secret keys.

Subject: Full Access Admin - not what it says it is?

To turn on Full Admin you need to do TWO things. Be listed in that special field in the server record, and put your self in full admin mode via Admin Client. Given how powerful the feature is we did not want someone to do this accidently or be in that mode all the time. They had to request to be in that mode explicitly.

With programatic access they need to turn it on with the special setting in the agent security tab in addition to being listed in the server record.

This is documented in the help.

Subject: Full Access Admin - not what it says it is?

But in the Notes Admin help it says that Full Access Administrator gives you:

Manager access, with all roles and access privileges enabled, to all databases on the server, regardless of the database ACL settings.

So, this should include the role to add groups to the NAB, shouldn’t it?

Subject: Full Access Admin - not what it says it is?

No… Full Access Administration means that you get to have manager access to all databases; not that you get every role available in the ACL.

There is no way to know if a role in the ACL is being used restrictively or not.

If the user required access to a role, he (as a manager) is free to update the ACL as required.

cheers,

Bram