Users Guide

Table Of Contents
Table 3. Role-based user privileges in OpenManage Enterprise (continued)
OpenManage
Enterprise features
Privilege Description User levels for accessing OpenManage Enterprise
Admin Device Manager Viewer
Network
management
Network actions / management Y N N
Group management Create, read, update and delete
(CRUD) for static and dynamic
groups
Y N N
Discovery
management
CRUD for discovery tasks, run
discovery tasks
Y N N
Inventory
management
CRUD for inventory tasks, run
inventory tasks
Y N N
Trap management Import MIB, Edit trap Y N N
Auto-deploy
management
Manage auto-deploy
configuration operations
Y N N
Monitoring setup Alerting policies, forwarding,
SupportAssist etc.
Y Y N
Power control Reboot / cycle device power Y Y N
Device configuration Device configuration, application
of templates, manage/migrate IO
identity, storage mapping (for
storage devices), etc
Y Y N
Operating system
deployment
Deploy operating system, map to
LUN, etc.
Y Y N
Device update Device firmware update,
application of updated baselines,
etc.
Y Y N
Template
management
Create / manage templates Y Y N
Baseline
management
Create / manage firmware /
configuration baseline policies
Y Y N
Power management Set power budgets Y Y N
Job management Job execution / management Y Y N
Report management CRUD operations on reports Y Y N
Report run Run reports Y Y Y
View View all data, report execution /
management etc.
Y Y Y
Scope-Based Access Control (SBAC) in OpenManage Enterprise
With the use of Role-Based Access Control (RBAC) feature, administrators can assign roles while creating users. Roles
determine their level of access to the appliance settings and device management features. Scope-based Access Control (SBAC)
is an extension of the RBAC feature that allows an administrator to restrict a Device Manager role to a subset of device groups
called scope.
While creating or updating a Device Manager (DM) user, administrators can assign scope to restrict operational access of DM to
one or more system groups, custom groups, and / or plugin groups.
Administrator and Viewer roles have unrestricted scope. That means they have operational access as specified by RBAC
privileges to all devices and groups entities.
16
Security features in OpenManage Enterprise