Summary

The Request By Attribute process allows a department administrator to request protected actions in the Austin Active Directory by crafting the request as a JSON string then adding the request to an attribute on the department's Administrative organizational unit (OU).

Overview

The Request By Attribute process is comprised of the following parts: the request string, the requests attribute, the request script, the result string, the results attribute.

Organizational Units

The Request By Attribute process is centered around each department's Adminstrative OU. The Administrative OU for a department is the OU that contains the resources managed by the Department User Tools such as department user accounts and the department's Department Adminstrators group.

Attributes

The Request By Attribute process relies upon the security of the attributes on each department's Administrative OU object. The attributes are confidential and cannot be accessed by default. Access to the attributes has been granted to the request process and each department's Department Administrators group.

The specific attributes and the permissions granted to the attributes are as follows:

Supported requests

The Request By Attribute process supports the following request types:

Planned requests

The Request By Attribute process is expected to support the following request types in the future: