...
...
...
...
...
...
- Full Control for the container that stores the system data (default name is “Indeed Identity”) and all of its descendant objects. To do so:
1. Open the Security property of the Indeed Identity container.
2. Click Add and specify the service account (servicecm).
3. Click Advanced, select the service account and click Edit.
4. Select the scope of This object and all descendant objects.
5. Set the Full control permission in the Permissions list.
6. Click ОК and then Apply.
- Permission to Read all Properties:
...
...
...
...
...
...
...
...
...
...
...
- Write: userAccountControl
- Write: thumbnailPhoto or Write: jpegPhoto
- Write: pwdLastSet
...
...
...
...
...
The permission to read all user properties is set for all domain accounts by default. If security policies prohibit reading of all user properties, then set the rights for the service account to read only required properties, according to the Table 3.
...
...
...
...
...
...
...
...
...
...
...
...
...
...
...
...
...
...
...
...
...
...
...
...
...
...
...
...
...
...
...
...
...
...
...
...
...
...
...
...
...
...
...
...