Owners Manual
Constraining Data Access | Serving Multiple Customer Accounts
664 OMNM 6.5.2 User Guide
Constraining Data Access
Constraining data access for a site involves two primary mechanisms:
Site ID Filtering
, also
referred to as Domain Id filtering, and the kind of filtering provided by
Access Profile Templates
.
The following diagrams how multitenancy can work.
Manage > Domain Access [Resources]
If you right-click a Managed Resource, you can select Manage > Domain Access to configure
different tenant domains’ access to the selected device.
Click the domain(s) (besides the master domain) where you want to have access to the device and
then click
Save.
Site ID Filtering
Site Management/organization site include an internal identifier. OpenManage Network Manager
automatically associates that Site ID with inventory entities created within the context of the site.
That Site ID then appears in any database filter whenever users retrieve data within the context of
a site, ensuring that the results come only from the site in context.
Service Provider Base
Permissions:
Administrator, universal.
Tenant#1
Permissions: T1 Access
Profile
User/Group: T1-Users
User/Group: T1-User#1
Permissions: T1 Role A/Permission set
User/Group: T1-User#2
Permissions: T1 Role B/Permission set
Tenant#2
Permissions: T2 Access
Profile
User/Group: T2-Users
User/Group: T2-User#1
Permissions: T2 Role A/Permission set
User/Group: T1-User#2
Permissions: T2 Role B/Permission set