Setting up an ITP/OnLine administrators group

By default access to the configuration pages of ITP/OnLine is restricted to members of the local Administrators group of the server that runs ITP/OnLine. In addition, access can be granted to users that do not need to be local administrators on the server. This step is required on Microsoft Windows platforms that support User Account Control (UAC) such as Microsoft Windows Server 2008, when User Account Control is enabled. Without a separate ITP/OnLine administrators group, it is not possible to administer ITP/OnLine on these platforms. On all other platforms, this step is optional.

To permit users to access the ITP/OnLine configuration pages, without making them a member of the local Administrators group, an alternative ITP/OnLine administrators group should be created and given the appropriate permissions. Users can then be given ITP/OnLine administration permissions by adding them to this group.

The ITP/OnLine administrators group should be granted the following permissions:

  1. Permissions on the Microsoft IIS metabase. How to set these rights for the ITP/OnLine administrators group is explained in section Set Microsoft IIS metabase permissions for the ITP/OnLine administrators group.
  2. The same file system authorization rights as the local Administrators group. These authorizations rights are mentioned in section Setting file system authorizations.