Users Guide

Security features in OpenManage Enterprise
Some of the security features of OpenManage Enterprise are:
User roles (Administrator, Device Manager, Viewer) with differing device management functionality.
Hardened appliance with Security-Enhanced Linux (SELinux) and an internal firewall.
Encryption of sensitive data in an internal database.
Use of encrypted communication outside the appliance (HTTPS).
WARNING: Unauthorized users can obtain OS-level access to the OpenManage Enterprise appliance bypassing Dell
EMC's security restrictions. One possibility is to attach the VMDK in another Linux VM as a secondary drive, and thus
getting OS partition access, whereby OS-level login credentials can possibly be altered. Dell EMC recommends that
customers encrypt the drive (image file) to make unauthorized access difficult. Customers must also ensure that for
any encryption mechanism used, they can decrypt files later. Else, the device would not be bootable.
NOTE:
Any change to the user role takes effect immediately and the impacted user(s) will be logged out of their active
session.
AD and LDAP directory users can be imported and assigned one of the OpenManage Enterprise roles (Admin,
DeviceManager, or Viewer).
Executing device management actions requires an account with appropriate privileges on the device.
Related information
Deploy and manage OpenManage Enterprise on page 17
Topics:
Role-based OpenManage Enterprise user privileges
OpenManage Enterprise user role types
Role-based OpenManage Enterprise user
privileges
Users are assigned roles which determine their level of access to the appliance settings and device management features. This feature is
termed as Role-Based Access Control (RBAC). The console enforces one role per account. For more information about managing users on
OpenManage Enterprise, see Manage OpenManage Enterprise users on page 129.
This table lists the various privileges that are enabled for each role.
Table 2. Role-based user privileges in OpenManage Enterprise
OpenManage Enterprise
features
User levels for accessing OpenManage Enterprise
Admin Device Manager Viewer
Run reports Y Y Y
View Y Y Y
Manage templates Y Y N
Manage profiles Y Y N
Manage baseline Y Y N
Configure device Y Y N
2
14 Security features in OpenManage Enterprise