Active Directory Group Membership Management
Hi guys,
There are a few similar threads I could find on adding a user to a group via a request offering but that is not quite what we are after.
What I would like to create is a request offering where a user could select a group and then have it auto enumerate the members of that group on the page. The user could then either just view, or add or remove users from the group.
Basically a total group managment RO that could be presented to some users who have delegated access to manage memberships of a particular group.
I have a feeling this may be beyond the portal and I might have to turn to another product like FIM.
If anyone has done something similar I would be really keen to hear your approach.
Thanks,
Steve
Answers
Alternatively you could also do this administration from the SCSM Console instead of making a request offering, but this still requires you to make a relationship and also a multi-instance listpicker on the group form. But overall I like the idea that AD membership is managed through your ITSM platform to get granular permissions and auditting history of who changed what when etc. Definitely best practice
I also believe that using SCSM catalog forms to manage this is best handled with many forms, rather than one. When you break it apart, your workflows are simpler.