Hi all !
Is there a way to protect the server documents against editing by goups with Manageraccess in the names.nsf ?
Read access should be possible.
Reason: Some personalmanagers with no sense for administration want manager access to names.nsf.
Some tipps?
Thanks
Subject: Don’t make them managers
I can think of no legitimate reason to make a non-administrator a manager in the directory. The question is why do they want to be managers versus what access they actually need.
The first question may be political and will require education on your part to explain the concept of the Notes security model. Make sure they know what it means to be a manager regarding capability and especially responsibility.
The second question is easier to address. For example, if they have a need to do specific tasks such as maintain membership of a particular group then all you need to do is make then an owner of that group document. (Group document/administration tab/owner field) Since the owner field is an authors field and ALL members of the organization should have author access to names.nsf (without create/delete rights they will be able to edit only the documents in names.nsf where they are listed as an author. This is just one example of granting users appropriate access to the directory.
There are many native options for refining access to elements within the directory (ACL/roles/levels of adminsitrators in server doc, xACL, etc.) The real issue becomes determiing users’ needs from wants.
Good luck!