Jump to content


Toby

Revoke software apporval?

Recommended Posts

Hi guys,

 

May have missed something obvious, but im looking for a way to revoke administrative approval for software deployment - at the moment 'approved' software stays approved, and you cannot delete it from approval requests. This is mainly for demo purposes, so that i can reset a demo lab, but im sure it would have a real world use also. :)

I'm comparing functionality here to RES Automation Manager orchestration, which does allow this functionality - but maybe this would be more a feature of opalis?

 

this is RC 1 btw.

Share this post


Link to post
Share on other sites

I am running RC 2 and I have the same question/issue. I can’t find a way to revoke approves once they have been granted.

 

One example (other than a fat fingered IT person clicking the wrong button and granting approval by accident) would be a finance person requesting access to a restricted finance app, this gets approved and works well until the user takes a new position somewhere else in the organization eg as a PA. Now the approval for the finance app can’t be removed and the user can pull this app down to any computer they wish. Not ideal.

 

Anyone worked out a solution to this?

Share this post


Link to post
Share on other sites

Unfortunately, the system does not provide a native revocation feature. Once the application has been approved for the user, it is available for them to install on any system. You can modify the requirements for the application to leverage the "primary user" rule - that would allow the user to only install the application on systems for which they are a primary user. You could also leverage those rules to query for properties that would indicate they are only allowed as a finance person, but not as a PA person. Additionally, targeting for the application catalog is based on collection membership, so if the finance person moved departements, and was no longer in the collection that allowed the application installation, they won't see it in the catalog.

 

Additionally, the system prioritizes "install" deployments over "uninstall" deployments. So, the user could be a member of two collections that both have the application targeted to the collections, one with an Install intent, and the other with an "uninstall" intent. The uninstall intent deployment would likely target devices, not users. As soon as the user is removed the from the "install" intent collection, the "uninstall" deployment takes effect and removes the application.

 

HTH

 

Dave

Share this post


Link to post
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

Loading...


×
×
  • Create New...

Important Information

We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.