Users Guide

Table Of Contents
146 Using iDRAC6 Directory Service
On the Active Directory side, a standard group object is used as a role group.
A user who has iDRAC6 access will be a member of the role group. To give
this user access to a specific iDRAC6 card, the role group name and its
domain name need to be configured on the specific iDRAC6 card. Unlike the
extended schema solution, the role and the privilege level is defined on each
iDRAC6 card, not in the Active Directory. Up to five role groups can be
configured and defined in each iDRAC6. Table 6-9 shows the default role
group privileges.
NOTE: The Bit Mask values are used only when setting Standard Schema with
the RACADM.
Single Domain Versus Multiple Domain Scenarios
If all of the login users and role groups, as well as the nested groups, are in the
same domain, then only the domain controllers’ addresses must be configured
on iDRAC6. In this single domain scenario, any group type is supported.
Table 6-9. Default Role Group Privileges
Role
Groups
Default Privilege
Level
Permissions Granted Bit Mask
Role
Group 1
None Login to iDRAC, Configure iDRAC,
Configure Users, Clear Logs,
Execute Server Control Commands,
Access Virtual Console, Access Virtual
Media, Test Alerts, Execute Diagnostic
Commands
0x000001ff
Role
Group 2
None Login to iDRAC, Configure iDRAC,
Execute Server Control Commands,
Access Virtual Console, Access Virtual
Media, Test Alerts, Execute Diagnostic
Commands
0x000000f9
Role
Group 3
None Login to iDRAC 0x00000001
Role
Group 4
None No assigned permissions 0x00000000
Role
Group 5
None No assigned permissions 0x00000000