Specifications

52
Creating Accounts
Principals in their basic form refer to the users of the system upon which the services are delivered.
Accounts are the means by which a principal is created within the system. An essential process in
building a robust and flexible system is defining what your principal base is.
This chapter details further what principals are and how the appliance manages these entities.
By the end of this chapter the reader should have a sound understanding of principals and how to
model their required principal architecture successfully.
Principal Types
Principals at their lowest level represent a user, a consumer of the system. This is simply a user that
will access the system. This can be in the form of a standard remote user accessing the system to carry
out their work, to a ‘power user’ that maintains the system and creates users and organizes access
control etc.
Principals however go one step further than this definition by incorporating the concept of ‘groups’– a
collection of users gathered into a single entity due to some similarities.
More details on groups can be found in the chapter titled, ‘Creating Groups’.
Administrator Account
The only default user embedded within the appliance is the administrator. If the user database has
been defined as built-in the user has the choice of providing authentication information for this user. If
however the selection is anything other than the built-in database, the appliance will load the defined
user list from within the database and the administrator is expected to choose from this list.
All other accounts throughout the system’s lifetime are created by this super user and their purpose
defined by their attached policies.
Structured!Acc ount!Network!
A!policy!structure!should!be!co nsidered!before! creating!any!acc ounts.!Categorizi ng!accounts!into!
policies!as!‘Administrators’!or! ‘ Guest’!will!encou rage!a!more!structured!and!organized!system.!
This!is!often!imperative!as!the!u ser!base!grows. ! !
The administrator however is not categorized as a standard user, in fact the administrator is classified
as the administrator of the system only and not as a typical user. The administrators purpose is to
perform configurations of the appliance and from then on the super user should delegate its
responsibilities out to other users of the system through access rights (Management Console > Access
Control >Access Rights).
Account Interface
The main accounts page provides information on all accounts present within the system.
Action Icons