{"id":770,"date":"2013-06-15T19:08:39","date_gmt":"2013-06-15T17:08:39","guid":{"rendered":"http:\/\/sccmfaq.wordpress.com\/?p=770"},"modified":"2013-06-15T19:08:39","modified_gmt":"2013-06-15T17:08:39","slug":"sccm-2012-rbac-add-computer-to-sccm","status":"publish","type":"post","link":"https:\/\/blog.hosebei.ch\/?p=770","title":{"rendered":"SCCM 2012 &#8211; RBAC: Add computer to SCCM"},"content":{"rendered":"<p>Hey, here&#8217;s Martin again.<\/p>\n<p>You often come across to the requirement, that you have give access to users to\u00a0the System Center 2012 Configuration Manager Console, that they can add new Computers to the Hierarchy to stage them with a Task Sequence. They only have to add them to a specific collection, nothing more: with Role based Administration not a problem. But when you try to achieve this, you\u00a0will often end up, that the users will have rights on the All Systems Collection, which you want to avoid when you Managing multiple sites or Servers and Workstations together. The Magic is behind the limiting collection. <!--more--><\/p>\n<p>That means, you will have to create a limiting collection, that you can use instead of the All System collection. Let me Show you how this is done, first I create a Role collection for all those Clients managed by the new role &#8220;ROL -All Clients for OSD&#8221;:<br \/>\n<a href=\"http:\/\/hosebei.wordpress.com\/wp-content\/uploads\/2013\/06\/rbac-osd01.png\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-medium wp-image-772\" alt=\"create limiting collection 01\" src=\"http:\/\/hosebei.wordpress.com\/wp-content\/uploads\/2013\/06\/rbac-osd01.png?w=300\" width=\"300\" height=\"272\" srcset=\"https:\/\/blog.hosebei.ch\/wp-content\/uploads\/2013\/06\/rbac-osd01.png 715w, https:\/\/blog.hosebei.ch\/wp-content\/uploads\/2013\/06\/rbac-osd01-300x273.png 300w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><\/a>Create a query rule to add only the designated Computer object to this collection, I decided to take all Workstations, queried by Name:<br \/>\n<a href=\"http:\/\/hosebei.wordpress.com\/wp-content\/uploads\/2013\/06\/rbac-osd02.png\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-medium wp-image-773\" alt=\"Query\" src=\"http:\/\/hosebei.wordpress.com\/wp-content\/uploads\/2013\/06\/rbac-osd02.png?w=265\" width=\"265\" height=\"300\" srcset=\"https:\/\/blog.hosebei.ch\/wp-content\/uploads\/2013\/06\/rbac-osd02.png 415w, https:\/\/blog.hosebei.ch\/wp-content\/uploads\/2013\/06\/rbac-osd02-265x300.png 265w\" sizes=\"auto, (max-width: 265px) 100vw, 265px\" \/><\/a>Confirm the Settings and don&#8217;t forget to activate &#8220;Use incremental Updates for this collection&#8221;, mind that there is a non-Technical Limit of 200 collections on which incremental updates should be activated (See <a href=\"http:\/\/technet.microsoft.com\/en-us\/library\/gg699372.aspx\">http:\/\/technet.microsoft.com\/en-us\/library\/gg699372.aspx<\/a>\u00a0for further information):<br \/>\n<a href=\"http:\/\/hosebei.wordpress.com\/wp-content\/uploads\/2013\/06\/rbac-osd04.png\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-medium wp-image-774\" alt=\"Collection\" src=\"http:\/\/hosebei.wordpress.com\/wp-content\/uploads\/2013\/06\/rbac-osd04.png?w=300\" width=\"300\" height=\"273\" srcset=\"https:\/\/blog.hosebei.ch\/wp-content\/uploads\/2013\/06\/rbac-osd04.png 716w, https:\/\/blog.hosebei.ch\/wp-content\/uploads\/2013\/06\/rbac-osd04-300x273.png 300w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><\/a>With this, you can create the collection you need, and to\u00a0which the users will add new\u00a0Computers\u00a0while using the SCCM Console by &#8220;Add Computer Information&#8221;. I will not Point out how to create another collection \ud83d\ude42<\/p>\n<p>After this is done, it is time to create the security role with permission for only the mentioned use. Those are the required permissions to add a Computer:<br \/>\nOn the collections: Read; Modify; Modify Resource; Delete Resource; Read Resource<br \/>\n<a href=\"http:\/\/hosebei.wordpress.com\/wp-content\/uploads\/2013\/06\/rbac-osd05.png\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-medium wp-image-776\" alt=\"RBAC Collection permission\" src=\"http:\/\/hosebei.wordpress.com\/wp-content\/uploads\/2013\/06\/rbac-osd05.png?w=284\" width=\"284\" height=\"300\" srcset=\"https:\/\/blog.hosebei.ch\/wp-content\/uploads\/2013\/06\/rbac-osd05.png 528w, https:\/\/blog.hosebei.ch\/wp-content\/uploads\/2013\/06\/rbac-osd05-284x300.png 284w\" sizes=\"auto, (max-width: 284px) 100vw, 284px\" \/><\/a>And on the site: Read; Import Computers<br \/>\n<a href=\"http:\/\/hosebei.wordpress.com\/wp-content\/uploads\/2013\/06\/rbac-osd06.png\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-medium wp-image-777\" alt=\"RBAC site permissions\" src=\"http:\/\/hosebei.wordpress.com\/wp-content\/uploads\/2013\/06\/rbac-osd06.png?w=285\" width=\"285\" height=\"300\" srcset=\"https:\/\/blog.hosebei.ch\/wp-content\/uploads\/2013\/06\/rbac-osd06.png 530w, https:\/\/blog.hosebei.ch\/wp-content\/uploads\/2013\/06\/rbac-osd06-285x300.png 285w\" sizes=\"auto, (max-width: 285px) 100vw, 285px\" \/><\/a><br \/>\nIf this is done, you can add your user or Group to SCCM:<br \/>\n<a href=\"http:\/\/hosebei.wordpress.com\/wp-content\/uploads\/2013\/06\/rbac-osd07.png\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-medium wp-image-781\" alt=\"Add security principal\" src=\"http:\/\/hosebei.wordpress.com\/wp-content\/uploads\/2013\/06\/rbac-osd07.png?w=282\" width=\"282\" height=\"300\" srcset=\"https:\/\/blog.hosebei.ch\/wp-content\/uploads\/2013\/06\/rbac-osd07.png 314w, https:\/\/blog.hosebei.ch\/wp-content\/uploads\/2013\/06\/rbac-osd07-283x300.png 283w\" sizes=\"auto, (max-width: 282px) 100vw, 282px\" \/><\/a>Add the designated security principal, the new limiting collection, and the collection to which the users should be able to add new devices. You can use the Default Security Scope:<br \/>\n<a href=\"http:\/\/hosebei.wordpress.com\/wp-content\/uploads\/2013\/06\/rbac-osd081.png\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-medium wp-image-784\" alt=\"add user or group\" src=\"http:\/\/hosebei.wordpress.com\/wp-content\/uploads\/2013\/06\/rbac-osd081.png?w=300\" width=\"300\" height=\"249\" srcset=\"https:\/\/blog.hosebei.ch\/wp-content\/uploads\/2013\/06\/rbac-osd081.png 691w, https:\/\/blog.hosebei.ch\/wp-content\/uploads\/2013\/06\/rbac-osd081-300x250.png 300w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><\/a>With this configuration, user Jukebox is able to add new devices and make a Membership rule to the designated collection. On the left side you see the console opened with Jukebox and adding a new Device, on the right side you see the same hierachry from an admin view:<br \/>\n<a href=\"http:\/\/hosebei.wordpress.com\/wp-content\/uploads\/2013\/06\/rbac-osd09.png\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-medium wp-image-785\" alt=\"Console add computer\" src=\"http:\/\/hosebei.wordpress.com\/wp-content\/uploads\/2013\/06\/rbac-osd09.png?w=300\" width=\"300\" height=\"166\" srcset=\"https:\/\/blog.hosebei.ch\/wp-content\/uploads\/2013\/06\/rbac-osd09.png 1849w, https:\/\/blog.hosebei.ch\/wp-content\/uploads\/2013\/06\/rbac-osd09-300x167.png 300w, https:\/\/blog.hosebei.ch\/wp-content\/uploads\/2013\/06\/rbac-osd09-1024x570.png 1024w, https:\/\/blog.hosebei.ch\/wp-content\/uploads\/2013\/06\/rbac-osd09-768x427.png 768w, https:\/\/blog.hosebei.ch\/wp-content\/uploads\/2013\/06\/rbac-osd09-1536x855.png 1536w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><\/a>With this permission the user can:<br \/>\n-They only see those devices which resides in the limiting collection (in this example the &#8220;ROL -All Clients for OSD&#8221;)<br \/>\n&#8211; Add Computers and add them to one collection<br \/>\n&#8211; Delete resources from the two collections (Remove &#8220;Delete Resource&#8221; from collection permission if not wanted)<br \/>\n&#8211; Modify collection Name and Membership rules of the two collections<br \/>\n&#8211; Clear PXE Flags on the devices they see and on the two collections<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Hey, here&#8217;s Martin again. You often come across to the requirement, that you have give access to users to\u00a0the System Center 2012 Configuration Manager Console, that they can add new Computers to the Hierarchy to stage them with a Task Sequence. They only have to add them to a specific collection, nothing more: with Role [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[13,27],"tags":[],"class_list":["post-770","post","type-post","status-publish","format-standard","hentry","category-collection","category-operating-system-deployment"],"_links":{"self":[{"href":"https:\/\/blog.hosebei.ch\/index.php?rest_route=\/wp\/v2\/posts\/770","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/blog.hosebei.ch\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blog.hosebei.ch\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blog.hosebei.ch\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/blog.hosebei.ch\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=770"}],"version-history":[{"count":0,"href":"https:\/\/blog.hosebei.ch\/index.php?rest_route=\/wp\/v2\/posts\/770\/revisions"}],"wp:attachment":[{"href":"https:\/\/blog.hosebei.ch\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=770"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blog.hosebei.ch\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=770"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blog.hosebei.ch\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=770"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}