Expand my Community achievements bar.

Don’t miss the AEM Skill Exchange in SF on Nov 14—hear from industry leaders, learn best practices, and enhance your AEM strategy with practical tips.
SOLVED

Why CUG not restricting auther to access the folder when it is not present in CUG?

Avatar

Level 7

I have added only 2 users into CUG on myfolder.

Logically only 2 users should to access myfolder.

But By using admin credentials I am able to access the myfolder.

Why this so?

Which ACL privilege makes admin to access all content?

1 Accepted Solution

Avatar

Correct answer by
Employee Advisor

The default name is "administrators" only, you can change the name, but not id.

Screenshot 2022-08-24 at 11.59.08 AM.png

View solution in original post

7 Replies

Avatar

Level 5

Administrators group is the exception to CUGs.  By default, if a user is a member of the administrators group, CUGs won't have an effect on them. 

Avatar

Level 7

Hi @sdouglasmc 

But admin is not part of Administrators group

akshaybhujbale_0-1661270358573.png

akshaybhujbale_1-1661270419856.png

Can we change the name of administrators group name in AEM.

 

 

 

Avatar

Employee Advisor

Admin user is a superuser, who can perform any action in AEM, so even if you have added any restriction on an action in AEM, admin can also perform this action.

Avatar

Level 7

so admin will have always name as "admin"? or there could be another name ?

And also how to make any user as admin?

 

Avatar

Employee Advisor

as per jackrabbit documentation [1], "The admin user is always being created. The ID of this user is retrieved from the user configuration parameter PARAM_ADMIN_ID, which defaults to admin."

 

You can create users and add them to Administrator groups.

 

[1] https://jackrabbit.apache.org/oak/docs/security/user/default.html

 

Avatar

Level 7

@Mohit_KBansal 

Thanks

What is the default name of administrators group ? Can we change the default name of administrators group?

Avatar

Correct answer by
Employee Advisor

The default name is "administrators" only, you can change the name, but not id.

Screenshot 2022-08-24 at 11.59.08 AM.png