How to give a group only the rights to add a profile to the objects in a directory, but not on the directory itself?


Question concerning Access Rights: Is there a possible configuration where you can give an group only the rights to add an profile to the objects in an directory, but not on the directory itself?

Unlucky me is working with idiots who keep assigning them to directories instead on workstation objects, after which I can clean their mess..😞

An option on the access rights on directory level which would enable this would be nice! 😉


Not as a general thing but you could remove the right to assign profiles on that folder, but then on each device (high effort IMHO).

I like the idea, tbh. Would you mind to post this idea in #feature-proposals ?


Hi @member, i have copied the message to that channel! 😉

Also had another idea for an workaround. I will create an test with 1 new directory @ the root level in the UMS, and give them write permissions there.

There they can assign policies, firmware updates etc, but i will diaable all possible logons on the igel device through an policy.

From there they can maintain the device, and move it to the correct directory, with updates firmware, assigned policies etc.

All write permissions on the other directories will be removed (but not denied as this will overrule the write config of the “maintain” directory.)

Continue reading and comment on the thread ‘ How to give an group only the rights to add an profile to the objects in an directory, but not on the directory itself?’.  Not a member? Join Here!

Learn more, search the IGEL Knowledge Base



Ask a question or comment on the above messasge thread?

Join or log in to the IGEL Community to ask us anything and meet other IGEL customers, partners, and EUC enthusiasts.

Submit a question, or Join Today!


Popular Message Threads


Categories & Tags: