Role Based Access
In general, the Role Based Access Control (RBAC) system allows for flexible administrator permissions via the assignment of OrganizationUnits (OU) and their underlying teams.
- A Tenant Management was implemented by adding a three-level OU Structure and Role Based Access with specific permissions.
We have further enhanced the self-service capabilities by introducing the user role of a “Tenant Administrator” and improving the user role of “Team Administrator”.
With this new role-based concept, you can administer users and teams in a secure and organized way.
Limitation- Tenant layer only available with manual user provisioning
In order to use the Tenancy feature you need to deactivate AD synchronization.
To disable AD sync:
- Head to the CIC component in your Topology settings.
- Disable the AD Sync by setting value for "EnabledAdTeamSync" to "false"
Any existing tenant definitions will remain unaffected by this change.
Summary of Roles with RBAC
Role | Configuration Source | Description |
---|---|---|
AdministratorSystem | Active Directory | System Administrators have full rights.
|
AdministratorSystemReadOnly | Active Directory | Read Only System Administrators can see all resources like a System Administrator but have no access to change anything in the system. |
AdministratorTenantExtended | Team Manager Configurator | Extended Tenant Administrators can....
|
AdministratorTenant | Team Manager Configurator | Tenant Administrators can…
|
AdministratorTeam | Team Administrator Configuration in TM FE Team Manager Configurator | Team Administrator can…
|
TeamMember | Team Membership Configuration in TM FE in case of manual user provisioning Active Directory in case of Active Directory synchronization | Team Member can ...
|