Users Guide

Table Of Contents
Security features in OpenManage Enterprise
Some of the security features of OpenManage Enterprise are:
Role-based access control allows different device management functionality for different user roles (Administrator, Device
Manager, Viewer).
Scope-based access control allows an administrator to determine the device groups that the device managers are expected
to manage.
Hardened appliance with Security-Enhanced Linux (SELinux) and an internal firewall.
Encryption of sensitive data in an internal database.
Use of encrypted communication outside the appliance (HTTPS).
Only browsers with 256-bit encryption are supported. for more information refer, Minimum system requirements for
deploying OpenManage Enterprise on page 20
WARNING: Unauthorized users can obtain OS-level access to the OpenManage Enterprise appliance bypassing
Dell EMC's security restrictions. One possibility is to attach the VMDK in another Linux VM as a secondary drive,
and thus getting OS partition access, whereby OS-level login credentials can possibly be altered. Dell EMC
recommends that customers encrypt the drive (image file) to make unauthorized access difficult. Customers
must also ensure that for any encryption mechanism used, they can decrypt files later. Else, the device would
not be bootable.
NOTE:
Any change to the user role takes effect immediately and the impacted user(s) will be logged out of their active session.
AD and LDAP directory users can be imported and assigned one of the OpenManage Enterprise roles (Admin,
DeviceManager, or Viewer).
Executing device management actions requires an account with appropriate privileges on the device.
Related information
Install OpenManage Enterprise on page 19
Topics:
OpenManage Enterprise user role types
Role and scope based access control in OpenManage Enterprise
OpenManage Enterprise user role types
NOTE:
AD and LDAP directory users can be imported and assigned one of the OpenManage Enterprise roles (Admin,
DeviceManager, or Viewer).
Actions run on the devices require a privileged account on the device.
Table 2. OpenManage Enterprise User role types
User with this role... Has the following user privileges
Administrator
Has full access to all the tasks that can be performed on the
console.
Full access (by using GUI and REST) to read, view, create,
edit, delete, export, and remove information related to
devices and groups monitored by OpenManage Enterprise.
2
14 Security features in OpenManage Enterprise