Administrative Domains : Managing ADOMs : Extend workspace to entire ADOM
 
Extend workspace to entire ADOM
When concurrent ADOM access is disabled, administrators are able to lock the ADOM. A right-click menu option has been added to allow you to lock/unlock ADOM access; see “Locking an ADOM”. The ADOM lock status is displayed by a lock icon to the left of the ADOM name. FortiManager v5.0 Patch Release 6 adds the ability to lock and edit the policy package independent from the ADOM lock.
The lock status is as follows:
Grey lock: The ADOM/Policy Package is currently unlocked, and is read/write.
Green lock: The ADOM/Policy Package is locked by you when logged in as an admin.
Red lock: The ADOM/Policy Package is locked by another admin.
An additional CLI command has been added to enable or disable ADOM/Policy Package lock override:
config system global
set lock-preempt [enable | disable]
end
When the ADOM/Policy Package lock override is enabled, if two administrators are concurrently accessing an ADOM/Policy Package and one attempts to lock the ADOM/Policy Package, the other administrator can kick the admin off the ADOM/Policy Package, preventing the ADOM/Policy Package from being locked.
 
Workspace is disabled by default, and is enabled on the CLI console. When workspace is enabled, the Device Manager and Policy & Objects tabs are read-only. You must lock the ADOM to enable read-write access to make changes to the ADOM.