Controlling Administrative Rights

You can create delegation rights that can be assigned to Active Directory organizational units (OUs) using a Visual Basic script file.

Access privileges are set in the system to allow or restrict administrative privileges. Administrative privileges are shown in the Connection panel of the Management Console. The system recognizes two types of administrators:

  • Enterprise administrators, who have complete, unrestricted administrative privileges.
  • Administrators, who have restricted administrative privileges.

About Ivanti Device and Application Control Access Control Rights

You can use the ctrlacx.vbs script to manage and show the user access control rights defined in the Active Directory hierarchy.

You can use the Visual Basic® script file, ctrlacx.vbs, to set, view, or modify the Manage Ivanti Device and Application Control Settings control rights in the Active Directory. This script allows Active Directory administrators to delegate administrative access to computers, users, user groups, and organizational units without allowing other task management, which is required by default, to the administrators.

Further information