Access Rights

Access rights let you manage ESMC Web Console users and their permissions.

The security model

These are key terms used in the security model:

Term

Explanation

Home Group

Home Group is the group where all objects (devices, tasks, templates, etc.) a user creates are automatically stored. Each user must only have one home group.

Object

Objects are located in Static Groups. Access to objects is by groups, not users (providing access by group makes it easy to accommodate multiple users, for example, if one user is on holiday). Server tasks and notifications are exceptions that require an "executing" user.

Access Group

Access Group functions as a static group which allows users to filter the location of the object based on access rights.

Administrator

A user that has home group All with a full Permission Set over the group is effectively an administrator.

Access Right

The right to access an object or to execute a task is assigned with a Permission Set. See the list of all access rights and their functions for more details.

Permission Set

A Permission Set represents the permissions for users that access ESMC Web Console. They define what the user can see or do in ESMC Web Console. A user can be assigned multiple Permission Sets. Permission sets are applied only over objects in defined groups. These Static Groups are set in the Static Groups section when creating or editing a permission set.

Functionality

A functionality is one type of object or action. Typically, functionalities get these values: Read, Write, Use. The combination of functionalities applied to an Access Group is called a Permission Set.

List of Access Rights related examples

There are various examples across Administration guide concerning access rights. This is a list of them:

How to duplicate policies

Difference between Use and Write

How to create a solution for branch office admins

How to share objects via duplication

How to divide access to certificates and authorities

How to allow user to create installers

How to remove notifications

How to create policies

Allow users to see all policies

Share licenses among branch admins