16.01.2013 Views

Microsoft Sharepoint Products and Technologies Resource Kit eBook

Microsoft Sharepoint Products and Technologies Resource Kit eBook

Microsoft Sharepoint Products and Technologies Resource Kit eBook

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Chapter 9: Capacity Planning 203<br />

More Info You can also define your own custom roles <strong>and</strong> site groups with<br />

different rights. For more information, it is strongly recommended that you<br />

read Chapter 24 to thoroughly underst<strong>and</strong> security before deploying Share-<br />

Point Portal Server.<br />

You should plan for the following roles <strong>and</strong> groups:<br />

■ Central administrator group (domain\CentralAdminGroup). Responsible<br />

for administration of the entire server farm, server farm topology, <strong>and</strong> virtual websites.<br />

This group must be a member of the SharePoint Portal Server administrators<br />

group <strong>and</strong> of the SQL Server system administrators group.<br />

Note You can register only one domain group as the SharePoint Portal<br />

Server administrators group. Therefore, if you want to include other members,<br />

you must add them using the user <strong>and</strong> group management tools for<br />

your domain.<br />

■ Corporate administrator group (domain\CorpAdminGroup). Responsible<br />

for managing site groups, managing list permissions, creating sites, creating portal<br />

sites, <strong>and</strong> viewing usage analysis data. The corporate administrator group cannot<br />

be customized or deleted, <strong>and</strong> there must always be at least one member of this<br />

group. Members of this group always have access to, or can grant themselves<br />

access to, any item in the website. This group needs to be a member of Domain<br />

Admins to import user profiles from Active Directory.<br />

■ Managing <strong>and</strong> updating news group. Based on your company business<br />

rules <strong>and</strong> security policies, you might need to create a group that only manages<br />

<strong>and</strong> updates the company news. In this case, be sure to remove inheritance<br />

permissions by selecting unique permissions. This will remove site-level permissions<br />

<strong>and</strong> provide news update rights only to the assigned group. For this<br />

accelerator, you need to create groups for the corporate portal site news area<br />

<strong>and</strong> also for each divisional news area.<br />

■ Managing <strong>and</strong> updating topics content group. Based on your company<br />

business rules <strong>and</strong> security policies, you might need to create a group for each<br />

topic area <strong>and</strong> assign separate groups for managing each topic or subtopic area<br />

in the corporate <strong>and</strong> divisional portal sites. In this case, you need to create<br />

groups that can update <strong>and</strong> upload documents to each topic area.

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!