unable to remove permission from admin group | Community
Skip to main content
Level 4
September 1, 2020
Solved

unable to remove permission from admin group

  • September 1, 2020
  • 3 replies
  • 1149 views

I have create a custom-admin group and that is inheriting all the properties from the OOTB Administrator group. But i dont want my group to have replicate permission, so im trying to remove them from my custom-group (after rinheriting from the OOTB group). but everytime i remove from/root, /apps, /content etc, and save and refresh, all the permissions are coming back again. what should i do?

This post is no longer active and is closed to new replies. Need help? Start a new post to ask your question.
Best answer by joerghoh

Why does your custom-administrators group inherit from the default "administrators" group? It's much easier if you don't do that and model that group from scratch.

 

(And besides that: even if your case would work, every member of this group has the write-acl permission, so they can add the replicate privilege at will.)

 

Jörg

3 replies

arunpatidar
Community Advisor
Community Advisor
September 1, 2020

Using deny can cause unexpected effects if the permissions are applied in a different order than the order expected. If a user is a member of more than one group, the Deny statements from one group may cancel the Allow statement from another group or vice versa. It is hard to keep an overview when this happens and can easily lead to unforeseen results, whereas Allow assignments do not cause such conflicts.

Adobe recommends that you work with Allow rather than Deny see Best Practices.

Arun Patidar
Singaiah_Chintalapudi
Level 7
September 1, 2020

Hi,

Can you give more details on the issue? Are you seeing the permissions back to the custom group you've created and removed the permissions or the users seeing the permission issue?

Thanks,

Singaiah

joerghoh
Adobe Employee
joerghohAdobe EmployeeAccepted solution
Adobe Employee
September 1, 2020

Why does your custom-administrators group inherit from the default "administrators" group? It's much easier if you don't do that and model that group from scratch.

 

(And besides that: even if your case would work, every member of this group has the write-acl permission, so they can add the replicate privilege at will.)

 

Jörg