
18
Managing Security Settings
Using Security Roles and Permissions
OpenManage Essentials provides security through role-based access control (RBAC), authentication, and encryption.
RBAC manages security by determining the operations run by persons in particular roles. Each user is assigned one or
more roles, and each role is assigned one or more user privileges that are permitted to users in that role. With RBAC,
security administration corresponds closely to an organization's structure.
OpenManage Essentials roles and associated permissions are as follows:
• OmeGuests is a default role assigned to all users at initial log in. No permissions are associated with this role,
and it is not displayed in the Windows user groups list. It enables administrators to monitor unauthorized users
attempting to access the console.
• OmeUsers have limited access and privileges and can perform read only operations in OpenManage Essentials.
They can log in to the console, run discovery and inventory tasks, view settings, and acknowledge events. The
Windows Users group is a member of this group.
• OmeAdministrators have full access to all the operations within OpenManage Essentials. Windows
Administrators group is member of this group.
• OmePowerUsers have the same privileges as OmeAdministraors except that they cannot edit preferences.
Microsoft Windows Authentication
For supported Windows operating systems, OpenManage Essentials authentication is based on the operating system's
user authentication system using Windows NT LAN Manager (NTLM) modules to authenticate. For the network, this
underlying authentication system allows you to incorporate OpenManage Essentials security in an overall security
scheme.
Assigning User Privileges
You do not have to assign user privileges to OpenManage Essentials users before installing OpenManage Essentials.
The following procedures provide step-by-step instructions for creating OpenManage Essentials users and assigning
user privileges for Windows operating system.
NOTE: Log in with administrator privileges to perform these procedures.
NOTE: For questions about creating users and assigning user group privileges or for more detailed instructions,
see the operating system documentation.
1. From Windows desktop, click Start → All Programs → Administrative Tools → Computer Management.
2. In the console tree, expand Local Users and Groups, and click Groups.
3. Double-click either the OmeAdministrators, OMEPowerUsers, or OmeUsers group to add the new user.
4. Click Add and type the user name that you are adding. Click Check Names to validate and then click OK.
New users can log on to OpenManage Essentials with the user privileges for their assigned group.
137
Kommentare zu diesen Handbüchern