Careful ... you can shoot yourself in the foot real easy.
If you have a lot of users to manage, then I suggest that you switch to LDAP-based authentication, where you can use a slew of existing utilities to easily manage large numbers of users, groups, and their associated attributes. This is pretty much just a management problem, but a very common one that applies in the general sense to all aspects of access-control. Your company probably already has a security team that's using similar tools, e.g. to manage the badge-readers at the doors. Leverage what they're already doing. LDAP (nee Microsoft OpenDirectory™), or Kerberos, is already more-than-sufficient to do this.
Last edited by sundialsvcs; 01-08-2015 at 10:00 AM.
|