Veritas NetBackup™ Appliance Security Guide
- About the NetBackup appliance Security Guide
- User authentication
- About user authentication on the NetBackup appliance
- About configuring user authentication
- About authenticating LDAP users
- About authenticating Active Directory users
- About authentication using smart cards and digital certificates
- About single sign-on (SSO) authentication and authorization
- About the appliance login banner
- About user name and password specifications
- User authorization
- Intrusion prevention and intrusion detection systems
- About Symantec Data Center Security on the NetBackup appliance
- About the NetBackup appliance intrusion prevention system
- About the NetBackup appliance intrusion detection system
- Reviewing SDCS events on the NetBackup appliance
- Running SDCS in unmanaged mode on the NetBackup appliance
- Running SDCS in managed mode on the NetBackup appliance
- Log files
- Operating system security
- Data security
- Web security
- Network security
- Call Home security
- Remote Management Module (RMM) security
- STIG and FIPS conformance
- Index
NetBackup appliance user role privileges
User roles determine the access privileges that a user is granted to operate the system or to change the system configuration. The user roles that are described in this topic are specific to LDAP and Active Directory (AD) users.
The following describes the appliance user roles and their associated privileges:
Table: User roles and privileges
User role | Privileges |
|---|---|
NetBackupCLI | Users can only access the NetBackup CLI. |
Administrator | Users can access the following:
|
AMSadmin | A user account that is assigned the AMSadmin role is provided administrative privileges to access the Appliance Management Console that is hosted on the AMS. An AMS user is allowed to perform all the functions on the Appliance Management Console and centrally manage multiple appliances. The AMS user cannot log on the NetBackup Appliance Shell Menu for AMS. An Administrator can create AMS users. |
A role can be applied to an individual user, or it can be applied to a group that includes multiple users.
A user cannot be granted privileges to both user roles. However, a NetBackupCLI user can also be granted access to the NetBackup Appliance Shell Menu in the following scenarios:
The user with the NetBackupCLI role is also in a group that is assigned the Administrator role.
The user with the Administrator role is also in a group that is assigned the NetBackupCLI role.
Note:
When granting a user to have privileges to the NetBackupCLI and the NetBackup Appliance Shell Menu, an extra step is required. The user must enter the switch2admin command from the NetBackup CLI to access the NetBackup Appliance Shell Menu.
Granting privileges to users and user groups can be done as follows:
From the NetBackup Appliance Web Console, on the page, click on the Grant Permissions link.
From the NetBackup Appliance Shell Menu, use the following commands in the Settings > Security > Authorization view:
Grant Administrator Group
Grant Administrator Users
Grant Administrator SSO_Groups
Grant Administrator SSO_Users
Grant NetBackupCLI Group
Grant NetBackupCLI Users
Grant AMS Group
Grant AMS Users
Grant AMS SSO_Groups
Grant AMS SSO_Users