We've had an issue that someone was granted FreeIPA admin on a cluster to activate student accounts, but that person deleted accounts instead of just activating/deactivating, which caused issues because usernames got reused. "admin" is too powerful, and a more limited set of permissions should be crafted for just the task of account activation/deactivation.
We've had an issue that someone was granted FreeIPA admin on a cluster to activate student accounts, but that person deleted accounts instead of just activating/deactivating, which caused issues because usernames got reused. "admin" is too powerful, and a more limited set of permissions should be crafted for just the task of account activation/deactivation.