On Mon, 30 Jul 2012 18:46:01 +0000, susehoush wrote:

> Hi,
>
> system:
> a few sles10sp3+oes2sp3 holding edir
> +
> 2 dsfw servers
> +
> 1 clusteres nss-volume
>
> If our windows admin puts some of our staff in the "Domain Admins" group
> with DSFW/Windows Tools these users suddenly get access to ALL the files
> of all departments and all user drives after they login to their
> machines.


Right. That's Domain Services for Windows emulating how Windows domains
work.


> These people should only be able to manage the servers in the domain but
> they should not see all the files. Is there any way to block this right?


Not really, no.


> (This is a very important legal issue in our company).


You may want to reconsider use of DSFW then. Or reconsider your
administrators and what they should and shouldn't be able to do.



--
--------------------------------------------------------------------------
David Gersic dgersic_@_niu.edu
Knowledge Partner http://forums.novell.com

Please post questions in the forums. No support provided via email.