Multiple permission levels

rated by 0 users
Not Answered This post has 0 verified answers | 1 Reply | 2 Followers

Not Ranked
2 Posts
Points 27
tloomos posted on Fri, May 1 2009 1:39 PM

I would like to setup the User Directory so that HR can edit everyone's title and manager, but individual users cannot modify their own title or manager. 

I tried setting a special group who can edit other peoples profiles, but that uses the same privileges as when a user is editing their own profile.  I realize the privs are based on the ActiveDirectoryConfig list, but it seems as though a field is either editable by everyone who has edit privs or not editable by anyone.

I would be fine with any approach to accomplish this.  A couple ideas I had (although I don't know if/how to get either of these implemented) are:

  • Create another ActiveDirectoryConfig list, create an additional web part page, add a new instance of the user directory part to this page and connect it to the new ActiveDirectoryConfig list.  However, I don't see an obvious way to point the web part to a different list.
  • Somehow install a 2nd instance of the web part with it's own config list and use this new web part on a separate page.  I doubt this approach is even possible

I'm open to any ideas on how I might accomplish this.

Thanks!!

All Replies

Top 10 Contributor
175 Posts
Points 2,916

Tloomos:

Your findings are correct.  Currently the only suggestion I have to accomplish exactly what you need would be to use our User Profile Plus Web Part that will allow you to specify user groups to edit user profiles.  The catch here is that this only hooks in to the WSS v3 user info. list and not in to AD.  To sync with the WSS v3 User Info. list with AD, you could use our User Profile Sync application.  I know this may not be exactly what you're looking for, but this will allow you to achieve your desired result.

Regards,

Jeremy Minich
    

Page 1 of 1 (2 items) | RSS
Bamboo Solutions Corporation, 2002-2010