<?xml version="1.0"?>
<rss version="2.0">
<channel>
<title>Thycotic Community - Secret Server - Nested Groups - Messages</title>
<link>http://www.thycotic.com/forums/messages.aspx?TopicID=247</link>
<description>Thycotic Community - Secret Server - Nested Groups - Messages</description>
<language>en-us</language>
<docs>http://blogs.law.harvard.edu/tech/rss</docs>
<generator>Jitbit AspNetForum</generator>
<pubDate>Tue, 09 Feb 2010 05:13:06 GMT</pubDate>
<lastBuildDate>Tue, 09 Feb 2010 05:13:06 GMT</lastBuildDate>
<item>
<link>http://www.thycotic.com/forums/messages.aspx?TopicID=247</link>
<title>Message from Jeremy A</title>
<description><![CDATA[Unfortunately the AD group nesting would not apply in our circumstance. <br/><br/>We have multiple AD Group Admins, who, by policy, are not administrators in Secret Server. If I used the group nesting for this purpose, then it would be possible for a security group administrator to give themselves elevated access in Secret Server by modifying their group membership.<br/><br/>Our only AD syncing is done by a single group which gives a user the ability to log into Secret Server. All rights and membership in Secret Server is contained in the application]]></description>
<pubDate>Tue, 09 Feb 2010 05:13:06 GMT</pubDate>
</item>
<item>
<link>http://www.thycotic.com/forums/messages.aspx?TopicID=247</link>
<title>Message from Jonathan</title>
<description><![CDATA[Unfortunately the AD integration is only available in the Installed Edition.  <img src="images/smilies/upset.gif" border=0 alt="upset" /> ]]></description>
<pubDate>Thu, 04 Feb 2010 12:28:39 GMT</pubDate>
</item>
<item>
<link>http://www.thycotic.com/forums/messages.aspx?TopicID=247</link>
<title>Message from Larry</title>
<description><![CDATA[Jeremy,<br/><br/>Is anything like ADSync available for the hosted solution?<br/><br/>thanks,<br/><br/>Larry]]></description>
<pubDate>Thu, 04 Feb 2010 12:16:02 GMT</pubDate>
</item>
<item>
<link>http://www.thycotic.com/forums/messages.aspx?TopicID=247</link>
<title>Message from Jonathan</title>
<description><![CDATA[Jeremy,<br/><br/>One workaround at present is to use the AD Sync.  You can then nest and manage your groups in AD and Secret Server will simply pull the groups in from AD.  Note that Secret Server will flatten the membership from AD - for example:<br/><br/>AD Group1 =&gt;  John, Steve<br/>AD Group2 =&gt;  Group1, Fred<br/><br/>If you sync both groups to Secret Server then:<br/><br/>SS AD Group1 =&gt; John, Steve<br/>SS AD Group2 =&gt; John, Steve, Fred<br/><br/>You can then assign these groups to roles and just do nesting in AD.<br/><br/>Hope that makes sense.<br/><br/>Thanks for the feedback!<br/><br/>:-D ]]></description>
<pubDate>Thu, 04 Feb 2010 11:55:55 GMT</pubDate>
</item>
<item>
<link>http://www.thycotic.com/forums/messages.aspx?TopicID=247</link>
<title>Message from Scott</title>
<description><![CDATA[Jeremy, thanks much for the feedback.<br/><br/>I will add this to our list of feature requests.<br/><br/><br/>best,<br/>Scott<br/>Thycotic Support]]></description>
<pubDate>Thu, 04 Feb 2010 09:00:34 GMT</pubDate>
</item>
<item>
<link>http://www.thycotic.com/forums/messages.aspx?TopicID=247</link>
<title>Message from Jeremy A</title>
<description><![CDATA[One feature I'd like to see is being able to nest groups inside other groups.<br/><br/>We've got a large user base with varying degrees of access, and it would make managing role memberships a lot easier with this ability]]></description>
<pubDate>Thu, 04 Feb 2010 04:44:46 GMT</pubDate>
</item>
</channel>
</rss>
