NetBackup™ Web UI Administrator's Guide
- Introducing the NetBackup web user interface
 - Monitoring and notifications
 - Section I. Configuring hosts
 - Section II. Configuring storage and backups
- Configuring storage
- About storage configuration
 - Create a Media Server Deduplication Pool (MSDP) storage server
 - Create a Cloud storage, OpenStorage, or AdvancedDisk storage server
 - Create a disk pool
 - Create a storage unit
 - Create a universal share
 - Using image sharing from the NetBackup web UI
 - Troubleshooting storage configuration
 - Troubleshooting universal share configuration issues
 - Create a Media Server Deduplication Pool (MSDP) storage server for image sharing
 
 - Managing protection plans
 - Managing classic policies
 - Managing backup images
 
 - Configuring storage
 - Section III. Managing credentials
- Managing credentials for workloads and systems that NetBackup accesses
- About credential management in NetBackup
 - Add a credential in NetBackup
 - Add a credential for an external KMS
 - Add a credential for NetBackup Callhome Proxy
 - Edit or delete a named credential
 - Add a credential for Network Data Management Protocol (NDMP)
 - Edit or delete Network Data Management Protocol (NDMP) credentials in NetBackup
 
 
 - Managing credentials for workloads and systems that NetBackup accesses
 - Section IV. Managing security
- Security events and audit logs
 - Managing security certificates
 - Managing host mappings
 - Managing user sessions
 - Managing the security settings for the primary server
- Certificate authority for secure communication
 - Disable communication with NetBackup 8.0 and earlier hosts
 - Disable automatic mapping of NetBackup host names
 - Configure the global data-in-transit encryption setting
 - About NetBackup certificate deployment security levels
 - Select a security level for NetBackup certificate deployment
 - Set a passphrase for disaster recovery
 - About trusted primary servers
 
 - Access keys
 - Configuring authentication options
 
 - Section V. Managing role-based access control
- About role-based access control in NetBackup
 - Configuring RBAC roles
- Configuring RBAC
- Notes for using NetBackup RBAC
 - Add AD or LDAP domains
 - Add a custom RBAC role
 - Edit or remove a role a custom role
 - View users in RBAC
 - Add a user to a role (non-SAML)
 - Add a user to a role (non-SAML, smart card user without AD or LDAP domain association or mapping)
 - Add a user to a role (SAML)
 - Remove a user from a role
 
 - Default RBAC roles
- Administrator
 - Default AHV Administrator
 - Default Cloud Administrator
 - Default NetBackup Command Line (CLI) Administrator
 - Default Kubernetes Administrator
 - Default NetBackup Kubernetes Operator Service
 - Default Microsoft SQL Server Administrator
 - Default Oracle Administrator
 - Default RHV Administrator
 - Default SaaS Administrator
 - Default Resiliency Administrator
 - Default Security Administrator
 - Default Storage Administrator
 - Default Universal Share Administrator
 - Default VMware Administrator
 
 
 - Configuring RBAC
 - RBAC permissions
- About role permissions
 - Global > BMR
 - Global > NetBackup Web Management Console Administration
 - Global > NetBackup management
- Access hosts
 - Agentless hosts
 - Anomalies
 - CLI sessions
 - Data classifications
 - Email notifications
 - Event logs
 - NetBackup hosts
 - Image sharing
 - NetBackup backup images
 - Jobs
 - Licensing
 - Media server
 - Remote primary server certificate authority
 - Resiliency
 - Resource limits
 - Retention levels
 - Servers > Trusted primary servers
 - Cloud providers
 - CloudPoint servers
 - WebSocket servers
 
 - Global > Protection
 - Global > Security
- Access control
 - Security events
 - Certificate management
 - Disaster recovery passphrase
 - Identity provider and SAML certificate configuration
 - Key Management Services (KMS)
 - Passphrase constraints
 - Service principal configuration
 - Global security settings
 - Trust versions
 - API keys
 - User certificates
 - User sessions and authentication
 
 - Global > Storage
 - Assets
 - Protection plans
 - Credentials
 - Manage access
 
 
 - Section VI. Managing detection and reporting
 - Managing deployment
 - Managing Resiliency Platforms
 - NetBackup SaaS Protection
 - NetBackup Flex Scale
 - Managing Bare Metal Restore (BMR)
 - Troubleshooting the NetBackup Web UI
 
User sessions and authentication
The permissions for user sessions and authentication allow users to view and manage the following:
See API keys.
See User certificates.
See User sessions.
These permissions allow a user to view and manage NetBackup API keys.
A NetBackup-authenticated user can view and manage their own API key using the web UI. If a user is not assigned to a role, the user can use the NetBackup APIs to manage their API key.
Table: RBAC permissions for API keys
Operation  | Description  | Additional required operations  | 
|---|---|---|
View  | View API keys.  | |
Create  | Create API keys.  | View  | 
Update  | Change the expiration date for an active API key.  | View  | 
Delete  | Delete API keys.  | View  | 
Manage access  | See Manage access.  | 
These permissions allow a user to view and manage the configuration that allows NetBackup authentication with user certificates or smart cards. Note: Authentication domains must be configured for the primary server before you can configure and enable smart card authentication.
Table: User certificates
Operation  | Description  | Additional required operations  | 
|---|---|---|
View  | View settings for smart card authentication.  | Security > Global security settings > Update  | 
Create  | Upload external CA certificates to the smart card authentication trust-store.  | Security > Global security settings > Update  | 
Delete  | Delete external CA certificates from the smart card authentication trust-store.  | Security > Global security settings > Update  | 
Manage access  | See Manage access.  | 
Note:
Users also need permissions to view the in User sessions. See NetBackup hosts.
These permissions allow a user to view and manage user sessions and user account settings.
Table: RBAC permissions for user sessions
Operation  | Description  | Additional required operations  | 
|---|---|---|
View  | View active user sessions.  | |
Update  | Enable, update, or disable sign-in banner configuration in the .  | View NetBackup management > NetBackup hosts > View  | 
Enable, update, or disable the following settings in the . 
  | Update NetBackup management > NetBackup hosts > View NetBackup management > NetBackup hosts > Create NetBackup management > NetBackup hosts > Update  | |
Approve user sessions  | Approve the NetBackup code-based session request.  | |
Close user session  | Close the selected user sessions.  | View  | 
Close all user sessions  | Close all user sessions. Without this permission, the administrator can only close the selected user sessions.  | View  | 
Unlock  | Unlock a user that has an account that is locked out of NetBackup.  | View locked  | 
View locked  | View any users that are locked out of NetBackup.  | |
Manage access  | See Manage access.  | View  |