The New Administrator wizard guides you through the steps to create either a new global, delegated administrator or an administrator group. For delegated administrator accounts, the global administrator can grant appropriate administration rights and views to perform specific administration tasks from the admin console.
Choose the Administrator Type:
Admin Group. An Admin Group is a distribution list (DL) that has been flagged as a delegated administrator DL. Administrator accounts you assign to this DL have the admin rights and views that have been granted to the DL.
Admin Account. An admin account is a user account that has Administrator enabled on the account. You can create a global administrator or a delegated administrator and grant specific views and rights to the delegated administrator account.
Click Next.
Create a new administrator account or administrator group. You can create the following:
When you click Next or Finished, the account is provisioned and will display in the Accounts list view.
If you clicked Next, you can select which admin views this administrator should have.
If you assigned a specific administrator role to the admin account, the Inherited Admin Views column on the Admin Views dialog displays the views associated with that role. You can select additional views from the Directly Assigned Admin Views column. Click Next.
The Configure the Grants dialog displays the rights required to display all the items in the selected directly assigned views. If you do not need to modify the rights associated with the views and do not want to grant additional rights, click Finish. The grants that are displayed are configured.
Click Next if you want to grant additional rights. The displayed grants are configured.
When the Information dialog opens, click OK.
If you do not want to grant these rights, but want to grant other rights at this time, click Skip. An empty Configure the Grants dialog displays.
If you click Next or Skip, you can configure Access Control Entries (ACE) for this admin account or group:
Click Add to add an ACE. Select the Target Type from the menu.
Enter the target's name. For example, domain_name@example.com. The name must be the same as configured in ZCS.
Select the type of right to grant, either System Defined Right or an individual Attribute Right.
If you select System Defined Right, you must enter the name of the right associated with that target. For a list of rights, see the Rights folder in the Overview Pane Configuration section.
If you select Attribute Right, you must select whether the right is read-only (get) or read and write (set).
If you do not know the attribute name, run the CLI zmprov describe to see the attribute names. (This list also includes attributes that cannot be set for delegated administration.)
The attribute right target type associated with the target type you selected are listed.
Enter the attribute associated with the right. The right name is created as you type.
Select whether this is a positive right or a negative right.
If this administrator can grant this right to another delegated administrator, check Can grant the right to other admins.
Click Add and More to add this right and open the Add ACE window again to add another right. Click Add and Finish to add this right and finish the configuration.
See the Administrator Guide Delegated Administration chapter, Specific Access Rights for examples of access rights for specific situations, such as setting up delegated administration roles to manage multiple domains, change passwords, or manage cross mailbox searches.
-------------------------------------------------------------------------------------------------------
Copyright @ 2005-2017 Synacor, Inc. All rights reserved. "Zimbra" is a registered trademark of Synacor, Inc.