Users Guide

Table Of Contents
View, add, enable, edit, disable, or delete the OpenManage Enterprise local users. For more information, see Add and edit
OpenManage Enterprise local users
Assign OpenManage Enterprise roles to Active Directory users by importing the directory groups. AD and LDAP directory
users can assigned an Admin, or a Device Manager, or a Viewer role in OpenManage Enterprise. For more information, see
Import AD and LDAP groups on page 147
View details about the logged-in users, and then end (terminate) a user session.
Manage Directory Services. For more information, see Add or edit Active Directory groups to be used with Directory
Services on page 149
View, add, enable, edit, disable, or delete OpenID connect providers (PingFederate and/or Key Cloak). For more information,
see OpenManage Enterprise login using OpenID Connect providers on page 151
By default, the list of users is displayed under Users. The right pane displays the properties of a user name that you select in the
working pane.
USERNAME: Along with the users you created, OpenManage Enterprise displays the following default user roles that cannot
be edited or deleted: admin, system, and root. However, you can edit the login credentials by selecting the default username
and clicking Edit. See Enable OpenManage Enterprise users on page 146. The recommended characters for user names are
as follows:
09
AZ
az
- ! # $ % & ( ) * / ; ? @ [ \ ] ^ _ ` { | } ~ + < = >
The recommended characters for passwords are as follows:
09
AZ
az
' - ! " # $ % & ( ) * , . / : ; ? @ [ \ ] ^ _ ` { | } ~ + < = >
USER TYPE: Indicates if the user logged in locally or remotely.
ENABLED: Indicates with a tick mark when the user is enabled to perform OpenManage Enterprise management tasks. See
Enable OpenManage Enterprise users on page 146 and Disable OpenManage Enterprise users on page 146.
ROLE: Indicates the user role in using OpenManage Enterprise. For example, OpenManage Enterprise administrator and
Device Manager. See OpenManage Enterprise user role types on page 14.
Related references
Disable OpenManage Enterprise users on page 146
Enable OpenManage Enterprise users on page 146
Related tasks
Delete Directory services on page 151
Delete OpenManage Enterprise users on page 146
Ending user sessions on page 148
Role and scope based access control in OpenManage Enterprise
OpenManage Enterprise has Role Based Access Control (RBAC) that clearly defines the user privileges for the three built-
in roles Administrator, Device Manager, and Viewer. Additionally, using the Scope-Based Access Control (SBAC) an
administrator can limit the device groups that a device manager has access to. The following topics further explain the RBAC
and SBAC features.
Role-Based Access Control (RBAC) privileges in OpenManage Enterprise
Users are assigned roles which determine their level of access to the appliance settings and device management features.
This feature is termed as Role-Based Access Control (RBAC). The console enforces the privilege required for a certain action
before allowing the action. For more information about managing users on OpenManage Enterprise, see Manage OpenManage
Enterprise users on page 141.
This table lists the various privileges that are enabled for each role.
142
Managing OpenManage Enterprise appliance settings