Can you assign scopes to groups?
Not sure if this is more of an eDir question vs. iManager.
Let's hypothesize:
Want to make another O in the tree. O=XYZ
This will contain users that are external to our system.
There will be certain people responsible for these users
Like:
O=XYZ
ou=users
ou=groups
But let's say there's going to be two "sets" of external users.
GroupA
GroupB
We want user1 to be responsible for GroupA users only (ie, they can only
add/delete/rename user objects if they're GroupA, and only change
passwords, etc. for GroupA).
User2 is for GroupB
Now, I'm pretty sure you CANNOT do this. At least the adding users part
(you have to add/create the user object first before you can put it into
a group membership). So I don't really see any mechanism to prohibit
User1 and User2 from creating group objects in "ou=users".
Short of re-designing the layout (ie: O=XYZ for "groupA" users and
O=LMN for "groupB" users)
And so forth.
Any ideas?
|