Is there a detailed list anywhere as to what each internal Security group is permitted to do?
I want to delegate the installation of patches to servers to another team here, but don't want them to be able to approve/decline patches at all, but am unsure as to which group would be the best fit.
Basically what I want this group to be able to do is:
Install Patches
Reboot Servers
RDP to Servers
What I don't want them to be able to do is
Approve or Decline patches
If I can also deny them access to specific Client Side groups ( eg Workstations ) that would be fantastic.
*Just found the Approval Delegation groups which I assume I can use to block the approval/Decline aspect. Does this setting take precedence over the rights granted by being a member of one of the Security Groups?