Authorization concept for administrators
Learn how the authorization concept for administrator accounts is structured and how it works.
Permissions
- For executing any kind of action in the Admin Console such as viewing token profiles or configuring a new data protection policy an administrator needs to have a permission.
- To an administrator only those menu items are displayed for which he has a permission.
- Without any permission assigned, the administrator will see an "Access denied" page after login. In this case the administrator can only change his own password and logout.
- Permissions are not assigned directly to an administrator, but they are assigned to one or more roles. These roles are then assigned to the administrator. Each role is tailored to a certain area of responsibility and includes the required permissions.
- It is ensured by the system that there is always at least one administrator
who has the following permissions:
- Show Roles
- Assign Roles
- Create and Edit Role
- Show Administrators
- Create and Edit Administrator
Roles
- Each role defines a set of permissions. A list of roles can be assigned to an administrator, who then has the cumulated permissions of all assigned roles.
- The built-in administrator account secRT has the role Global Administrator assigned automatically.
- If an administrator is currently logged in, a change in role assignment will be effective immediately after a page-refresh. Otherwise, the role assignment will take effect the next time the administrator logs in.
- An administrator cannot edit or delete a role assigned to himself.
- You can also define and assign your own roles. However, the predefined roles cannot be edited or deleted.
- The following roles are predefined:
Table 1. Predefined roles Role Permissions (1) Global Administrator All permissions are assigned, including the permissions to activate/deactivate an approval process in and to approve or reject a change request. Note: By default, the permissions Activate / Deactivate Change Requests and Approve or Reject Change Request are assigned only to the Global Administrator role. However, you have the option to assign the permissions to a self-created administrator role.Permissions related to the SharePoint-Adapter:- Show SharePoint Configuration
- Edit SharePoint Configuration
Permissions related to the WebDav-/Testdata-Adapters:- View Policy Configuration
- Edit Policy Configuration
(2) Application Manager Permission to create and edit apps, templates, proxies, SSO Proxy and starting/stopping services. Permissions related to the SharePoint-Adapter:- Show SharePoint Configuration
- Edit SharePoint Configuration
Permission to view the token profiles in the Token tab.
Permission to display, configure and execute features related to any adapter.
(3) Permission Manager Permission to define roles. (4) Administrator Manager Permission to create, edit, activate & deactivate administrators, to assign roles and to edit the mapping of Active Directory roles to administrator roles. (5) Key Manager All key related permissions. (6) License Manager Permission to see and modify licensing. (7) Salesforce Policy Manager Note: This role is only available if you have additionally installed the eperi sEcure Salesforce.- Permission to view and modify the Salesforce data protection policy.
- Permission to view and change the scheduling details for background indexing.
- Permission to view and change the scheduling details for background protection.
- Permission to view the token profiles in the Token tab.
(8) Auditor Permission to view Salesforce/Office365 policy. View List of Keys. View SSO Proxy configuration. View List of Users. Show Admins. Show roles and status. Show license. View password policy. View Master Key settings. No edit permissions. Permission related to the SharePoint-Adapter:- Show SharePoint Configuration
