Setting up and managing user accounts
User accounts, user authentication, and user authorization can be defined and managed in either of two ways: in Microsoft Active Directory (Version 2 or 3) LDAP (Lightweight Directory Access Protocol) server, or in an internal OnCommand Insight user database. Having a different user account for each person provides a way of controlling the access rights, individual preferences, and accountability. Use an account that has Administrator privileges for this operation.
Before you begin
You must have completed the following tasks:
-
Install your OnCommand Insight licenses.
-
Allocate a unique user name for each user.
-
Determine what passwords to use.
-
Assign the correct user roles.
If you are importing an LDAP certificate and have changed server.keystore and/or server.trustore passwords using securityadmin, restart the sanscreen service before importing the LDAP certificate. |
Security best practices dictate that administrators configure the host operating system to prevent the interactive login of non-administrator/standard users. |
Steps
-
Open Insight in your browser.
-
On the Insight toolbar, click Admin.
-
Click Setup.
-
Select the Userstab.
-
To create a new user, click the Actions button and select Add user.
You enter the Name, Password, Email address, and select one of the user Roles as Administrator, User, or Guest.
-
To change a user's information, select the user from the list and click the Edit user account symbol to the right of the user description.
-
To remove a user from the OnCommand Insight system, select the user from the list and click Delete user account to the right of the user description.
Results
When a user logs in to OnCommand Insight, the server first attempts to authenticate through LDAP, if LDAP is enabled. If OnCommand Insight cannot locate the user on the LDAP server, it searches in the local Insight database.