The user is defined in domain “global” but has access to subdomains only. The user is a
“Domain Administrator” in subdomain “d1,” but has a custom role r1 for subdomain “d2.”
Configuring Roles
To assign a role to the new administrator, select the
Permissions
tab and choose a role
for the new administrator. When you assign a role to an NSM administrator, the
administrator can perform the predefined system activities specified in that role.
You can select a default or custom role for that administrator. NSM includes default roles
for common job responsibilities:
•
Domain Administrator—Can perform all activities in the domain.
•
Read-Only Domain Administrator—Can perform all read-only activities in the domain.
•
IDP Administrator—Can perform all IDP activities. All other activities are excluded.
•
Read-Only IDP Administrator—Can perform all read-only IDP activities.
•
System Administrator—Can perform all system-wide activities, Domain Administrator
activities, and IDP Administrator activities.
•
Read-Only System Administrator—Can perform all read-only system-wide activities
and Domain Administrator activities.
Each default role contains activities that relate to the traditional responsibilities for a
specific job title. Use a default role to create quickly an NSM administrator or to create
administrators when your organization’s existing permission structure maps closely to
the permissions defined in the default role.
All roles, default and custom, are created from activities. In a default role, the activities
are chosen for you; in a custom role, you choose the activities that make up the desired
functionality. See “Creating Custom Roles” on page 74 for details.
NOTE:
Role assignment is additive. When you assign multiple roles to a single
administrator, the permissions specified by the activities in the role are added.
You must also select a domain. You can assign administrators to the global domain, or
to one or more subdomains (the subdomain must already exist). Administrators must
log in to the domain they were created in. For example, the super administrator has access
to all domains, but must log in to the global domain first, and then switch to a subdomain
using the domain menu. For details on creating a subdomain, see “Creating Subdomains”
on page 90.
Creating Custom Roles
For more complex and diverse permissions requirements, create custom roles to specify
the exact level of permission you want to give an administrator. An
activity
is a predefined
task that defines access to a function in NSM. To assign one or more activities to an NSM
administrator, create a role that includes those activities and assign the role to the
administrator.
Copyright © 2010, Juniper Networks, Inc.
74
Network and Security Manager Administration Guide
Summary of Contents for NETWORK AND SECURITY MANAGER 2010.3
Page 6: ...Copyright 2010 Juniper Networks Inc vi...
Page 36: ...Copyright 2010 Juniper Networks Inc xxxvi Network and Security Manager Administration Guide...
Page 52: ...Copyright 2010 Juniper Networks Inc 2 Network and Security Manager Administration Guide...
Page 90: ...Copyright 2010 Juniper Networks Inc 40 Network and Security Manager Administration Guide...
Page 144: ...Copyright 2010 Juniper Networks Inc 94 Network and Security Manager Administration Guide...
Page 146: ...Copyright 2010 Juniper Networks Inc 96 Network and Security Manager Administration Guide...
Page 234: ...Copyright 2010 Juniper Networks Inc 184 Network and Security Manager Administration Guide...
Page 310: ...Copyright 2010 Juniper Networks Inc 260 Network and Security Manager Administration Guide...
Page 364: ...Copyright 2010 Juniper Networks Inc 314 Network and Security Manager Administration Guide...
Page 366: ...Copyright 2010 Juniper Networks Inc 316 Network and Security Manager Administration Guide...
Page 478: ...Copyright 2010 Juniper Networks Inc 428 Network and Security Manager Administration Guide...
Page 576: ...Copyright 2010 Juniper Networks Inc 526 Network and Security Manager Administration Guide...
Page 580: ...Copyright 2010 Juniper Networks Inc 530 Network and Security Manager Administration Guide...
Page 592: ...Copyright 2010 Juniper Networks Inc 542 Network and Security Manager Administration Guide...
Page 684: ...Copyright 2010 Juniper Networks Inc 634 Network and Security Manager Administration Guide...
Page 690: ...Copyright 2010 Juniper Networks Inc 640 Network and Security Manager Administration Guide...
Page 696: ...Copyright 2010 Juniper Networks Inc 646 Network and Security Manager Administration Guide...
Page 698: ...Copyright 2010 Juniper Networks Inc 648 Network and Security Manager Administration Guide...
Page 748: ...Copyright 2010 Juniper Networks Inc 698 Network and Security Manager Administration Guide...
Page 778: ...Copyright 2010 Juniper Networks Inc 728 Network and Security Manager Administration Guide...
Page 870: ...Copyright 2010 Juniper Networks Inc 820 Network and Security Manager Administration Guide...
Page 872: ...Copyright 2010 Juniper Networks Inc 822 Network and Security Manager Administration Guide...
Page 898: ...Copyright 2010 Juniper Networks Inc 848 Network and Security Manager Administration Guide...
Page 908: ...Copyright 2010 Juniper Networks Inc 858 Network and Security Manager Administration Guide...
Page 910: ...Copyright 2010 Juniper Networks Inc 860 Network and Security Manager Administration Guide...
Page 995: ...PART 6 Index Index on page 947 945 Copyright 2010 Juniper Networks Inc...
Page 996: ...Copyright 2010 Juniper Networks Inc 946 Network and Security Manager Administration Guide...