I may be a complete idiot (very likely) but I am following the directions step by step to setup FCS. It says that roles can be assigned to users (IE, Client Security Administrator, Policy Author, Policy Deployer, etc) but where can I find the spot to assign these roles??
It's driving me completely insane!!!!!!
I'd be interested in knowing where it says that you can assign user roles to an FCS deployment?
Natively FCS does not support assigning user roles. If you want security execs do be able to see reports but nothing else you can setup sql reporting to send these persons an email with the reports.
Depending on where you are in the docs, you may have not got to the section that shows how to define these roles.
As Johan said, there aren't really any "out the box" roles that can be defined, but the idea i think is that you can use the above roles to then create groups/users and assign them the appropriate permissions
Have a look at http://technet.microsoft.com/en-gb/library/bb418964.aspx this goes through the required permissions you need based on the roles as a sub-link from the description of each role. It's pretty much a case of assigning them all manually - mostly being SQL, AD and MOM permission that need to be assigned
I normally create some groups with similar concepts to what they describe, assign all the permisisons and you can then just add/remove users nice and easily as required in the future
Hope this helps, if you get stuck assigning any of them, post back and we can try and help
Actually I am reading the "Clinic 6079: Managing and Troubleshooting Opetarion in Microsoft Forefront", and in inside the "Managing Microsoft Forefront Client Security" there is a section called "Configuring Forefront Client Security at High Level" it says:
"The administrative tasks that are available in Forefront Client Security are distributed among four user roles. To enable the administrative users to perform the tasks that are required for their assigned roles, you can grant the users the appropriate permissions and Dashboard access."
After reading this I assumed there were 4 roles created for the administration of FCS and that I didn't have to make them manually, though I haven't been able to find them. Maybe the creation of a script would be usefull.