User Guide
Administration.....45
For example, if an administrator configures the appliance to restrict user access to a target, the
administrator can assign users to groups that are authorized for specific target access. The
administrator can also authorize groups for power management and data buffer management.
This document and the software refer to users whose accounts are configured on remote
authentication servers as remote users. Remote users do not need local accounts.
LDAP authentication services allow group configuration. If a remote user is configured as a
member of a remote group, the authentication server provides the group name to the appliance
when it authenticates the user. A local group by the same name must also be configured on the
appliance. If an authentication server authenticates a remote user but does not return a group, then
the remote user is, by default, assigned to the user group.
Managing user groups
Administrators can create custom user groups that contain any users. Permissions and access for
custom user groups will be determined by the top-level user group permissions.
To add or modify a user group:
1. From the sidebar, click Users - Groups.
2. Click Add to create a new user group. The Create User Group screen appears. Enter the new
user group name and use the drop-down menu to define the user group role (User, Power-
User or Admin).
-or-
Click the name of a group to modify. The Modify Group screen appears. Use the drop-down
menu to change the user group role.
3. Define the pre-emption level.
4. Check the box to enable the session time-out and enter the number of minutes for the time-out
in the field.
5. To add users to the group, move users from the Available Users box on the left to the box on
the right by selecting the name and clicking the Add button. You can remove any users from
the group by selecting them from the box on the left and clicking the Remove button.
6. Click Add.
Appliance Administrator group
Members of the Appliance Administrator group have full administrative privileges that cannot be
changed, the same access and configuration authorizations as the default admin user.