Installation and Operation Manual

Table Of Contents
TD 92579EN
10 April 2015 / Ver. N
Installation and Operation Manual
IP-DECT Base Station & IP-DECT Gateway (software version 7.2.X)
35
23 Note: This step is only applicable if "Use domain group" is selected in the
Authorization drop-down list, see above.
In the Ad
min Group RID text field, specify the Relative Identifier (RID) of a Windows
group with administrator rights.
In the Aud
itor Group RID text field, specify the Relative Identifier (RID) of a
Windows group with auditor rights.
The RID is the last part of the Security Identifier (SID) of a group.
Here is an example of a SID where the last f
ive digits (in bold) are the RID: S-1-5-21-
4151926548-1272113248-3927039109-11265.
To determine the SID of a group, do as follows:
1.
Start Windows Command Prompt (cmd.exe). To find Windows Command
Prompt, enter "cmd.exe" in Windows Start Menu search field.
2.
In Windows Command Prompt, enter "whoami /groups". This command
displays the group information of the user logged in to the Windows domain.
24 Click "OK".
About security groups in AD
Groups are characterized by their scope and their type (security or distribution).
Using security groups, you can assign user rights to security groups in AD.
The scope of a security group determines the extent to which the security group is
applied within a
domain or forest. There are three scopes that can be selected when
creating a security group:
Universal - Can
contain users/universal groups/global groups from all domains
in the forest. Can PARTLY be used in trusted domains, but maybe makes little
sense as only users/groups of the trusted domain will work in IP-DECT.
Global - Can on
ly contain users/global groups from the same domain. Can be
used in trusted domains.
Doma
in Local - Can contain any users/universal groups/global groups of the
forest and domain local groups of the same domain. Can NOT be used in
trusted domains.
With the above said, it is recommended to select Global as scope for security group.
On IPBS1, IPBS2 and IPBL (the client):
25 Select General > Admin.