NetBackup™ Web UI Administrator's Guide
- Introducing the NetBackup web user interface
- Section I. Managing security
- Monitoring and notifications
- Managing role-based access control
- About role-based access control (RBAC) in NetBackup
- Configuring RBAC
- Role permissions
- Global > NetBackup management
- Access hosts
- Email notifications
- Data classification
- Event logs
- NetBackup hosts
- Image sharing
- NetBackup backup images
- Jobs
- Licensing
- Media server
- Remote master server certificate authority
- Resiliency
- Resource limits
- Retention levels
- Servers > Trusted master servers
- Cloud providers
- CloudPoint servers
- WebSocket servers
- Global > Protection
- Global > Security
- Global > Storage
- Assets
- Protection plans
- Credentials
- Global > NetBackup management
- Manage access
- Configure an external certificate for the NetBackup web server
- Security events and audit logs
- Managing security certificates
- Managing user sessions
- Managing master server security settings
- Certificate authority for secure communication
- Disable communication with NetBackup 8.0 and earlier hosts
- Disable automatic mapping of NetBackup host names
- About NetBackup certificate deployment security levels
- Select a security level for NetBackup certificate deployment
- Set a passphrase for disaster recovery
- About trusted master servers
- Creating and using API keys
- Configuring authentication options
- Managing hosts
- Troubleshooting the web UI
- Section II. Managing storage and backups
- Configuring storage
- About storage configuration
- Create a Media Server Deduplication Pool (MSDP) storage server
- Create a Cloud (Cloud Catalyst), OpenStorage, or AdvancedDisk storage server
- Create a disk pool
- Create a storage unit
- Create a universal share
- Using image sharing from the NetBackup Web UI
- Troubleshooting storage configuration
- Troubleshooting universal share configuration issues
- Managing protection plans
- Managing protection plans for Microsoft SQL Server
- Usage reporting and capacity licensing
- Configuring storage
- Section III. Veritas Resiliency Platform
- Section IV. Managing credentials
Role permissions
Role permissions define the operations that roles users have permission to perform.
Table: Role permissions for NetBackup RBAC
Category | Description | ||
|---|---|---|---|
Global permissions apply to all assets or objects. For example, in NetBackup 8.3, or permissions cannot be applied to specific jobs or hosts. A role with or permissions apply to all jobs or hosts. | |||
Configuration and management of NetBackup. | |||
NetBackup backup policies and storage lifecyle policies. See Global > Protection. | |||
NetBackup security settings. See Global > Security. | |||
Manage backup storage settings. See Global > Storage. | |||
Manage assets Cloud, Microsoft SQL Server, RHV, Universal shares, and VMware. See Assets. Note: Assets can only be added when you create a role and cannot be added to an existing role. | |||
Manage how backups are performed with protection plans. See Protection plans. Note: Protection plans can only be added when you create a role and cannot be added an existing role. | |||
Manage credentials for Microsoft SQL Server and external KMS. See Credentials. Note: Credentials can only be added when you create a role and cannot be added to an existing role. | |||
Note the following when you configure the permissions for RBAC roles:
RBAC only controls access to the web UI and not the NetBackup Administration Console.
When you create roles, be sure to enable the minimal number of permissions so the user can sign in to and use the web UI. Some individual permissions do not have a direct correlation with a screen in the web UI. Users that attempt to sign in but that only have a permission of this kind receive an "Unauthorized" message.
If a user is added to or removed from a role, the user must sign out and sign in again before the user's permissions are updated.
Most permissions are not implicit.
In most cases a permission does not give a user permission. A permission does not give a user permission or other recovery options like .
Not all RBAC-controlled operations can be used from the NetBackup web UI. (For example, NetBackup backup images can only be viewed and managed from the APIs or the NetBackup Administration Console.) These types of operations are included in RBAC so a role administrator can create roles for API users as well as web UI users.
Some tasks require a user to have permissions in multiple RBAC categories. For example, to establish a trust relationship with a remote master server, a user must have permissions for both and .