User's Manual

22 Kaspersky Administration Kit
granting to users and groups of users access rights to access the
functionality of Kaspersky Administration Kit.
After installation of the Administration server, users included into groups
KLAdmins and KLOperators will be by default granted rights to connect to the
Server and to work with the logical network.
Group data will be created during the installation of the Administration server
component irrespective of the account selected to launch the Administration
server service:
in the domain that includes the Administration server and on the Admini-
stration server computer, if the Administration server is launched under an
account of a user included into this domain;
only on the Administration server computer if this Sever is launched under
the system account.
Group KLAdmins will be granted all rights: Reading, Execution, Writing.
Group KLOperators will be granted rights Reading. The set of rights granted to
KLAdmins cannot be modified.
Users included into group KLAdmins will be called logical network
administrators, users included into group KLOperatorslogical network
operators.
Groups KLAdmins and KLOperators can be viewed and required changes can
be made using standard Windows OS administration tools – Administration /
Local users and groups.
In addition to users included into group KLAdmins the logical network
administrator's rights will be granted to:
domain administrators, computers of which are included into the structure
of this logical network;
local administrators of computers on which the Administration server is
installed.
All operations initiated by the logical network administrators will be performed
with the rights of the Administration server account. For each Administration
server a KLAdmins group of its own can be created that will have rights applied
within this particular logical network only.
If computers related to one domain create several logical networks, the domain
administrator will be the administrator of each logical network formed this way. In
this case such logical network will share the same group KLAdmins that will be
created during the installation of the first Administration server. New members
can be added to this group using the operating system's administration tools.
Operations initiated by the logical network administrators will be performed with
the rights of the corresponding Administration server.
The rights of users in Kaspersky Administration Kit application are determined
based on the user Windows authentication in the network.