ManageEngine® SQLDBManager Plus User Administration | ||
SQLDBManager Plus permits three types of user access to work with the product. The different roles are User, Operator, and Administrator.
User : As a system user, you will have read-only access to all components of the product. Users will not have the privilege to access, configure or edit the different components of the product. To delete a user, a user must log in as default Administrator.
Operator: The system operators have read-only access to only those components of the product that the administrator assigns to the operator. The operator role does not have the privilege to access, configure or edit the different components of the product. If an operator is part of a Monitor Group, then the restrictions will be in effect only for the operator and not others.
Administrator: The system administrators are allowed to perform all admin activities. The administrator role also have the privilege to configure user administration.
In the Admin page, click User Administration under SQLDBManager Plus Server Settings to browse through the following tabs:
SQLDBManager Plus provides you with the ability to manage users and roles for your enterprise, with roles assigned to users and different permissions associated to each role. This is achieved by first adding users and associating the users with the roles.
You can also import users from Active Directory or LDAP. This functionality is implemented as a more convenient method to add a large number of users and to ease the user administration in SQLDBManager Plus. You can import users and perform role configuration for LDAP and Active Directory users and groups in SQLDBManager Plus.
Add new users to SQLDBManager Plus
The system administrators are allowed to perform all admin activities as explained in Performing Admin Activities. The admin role also has the privilege to configure user administration as explained below.
In Admin page, click User Administration under SQLDBManager Plus Server Settings. This lists the User Profile(s) that consists of the User name and the role.
To add a new user, click Add new. This opens the 'New User' screen.
Specify a unique user name and provide a password.
Provide a description and an e-mail for the user (optional).
Assign a role to the user (User/ Operator/ Administrator ).
You can upload a profile photo for the user in jpg, gif, png or jpeg format(optional). A file size less than 100 KB is preferred.
You can select user groups to give a group of users the same previleges as the new user. (Not applicable to users without Operator, or Administrator roles).
Select the monitor group to which the new user or users must be granted previleges.(Not applicable to users without Operator or Administrator roles).
Click Create User. The new user or user groups will be displayed in the User Profile(s) table displaying the status, description, e-mail address,role and the monitor groups assigned.
Note
The default user access of SQLDBManager Plus is admin (Administrator). All users log into SQLDBManager Plus as Admin users and are given all the administrative privileges to work with the tool.
You can also assign the owners for the Monitor Groups while creating the Monitor Groups or while editing the existing Monitor Groups
Importing users from active directory or LDAP
You can import users and perform role configuration for LDAP and Active Directory users and groups in SQLDBManager Plus.
Users imported from the Active Directory or LDAP can login into SQLDBManager Plus using their Active Directory/LDAP credentials. Since user authentication is done in the Domain Controller all the account policy regulations of the company/domain is automatically inherited to SQLDBManager Plus credentials also.
In Admin page, click User Administration under SQLDBManager Plus Server Settings. This lists the User Profile(s) that consists of the User name and the role.
Click the Import Users from Active Directory / LDAP link under the list of user profile
Select a domain name from the drop-down list.
Adding a New Domain
You can select an already added domain from the drop-down list or add a new domain. You can also edit the existing Domain controller settings in the same manner.
Select the Add New Domain option from the Domain Name drop-down list.
Enter the following details:
Domain Name: Name of the domain from where the users need to be imported.
Domain Controller: The hostname or the IP address of the DNS server for the domain.Domain Port: The port of the DNS server.
Authentication Type: LDAP or Active Directory.
Username and Password: The active directory username of the domain user should be provided in DOMAIN\username format. The LDAP user name should be provided in cn=user,dc=domain,dc=name format.
Search Filter: To filter out search result you can use characters followed by * as well as the role criterion in LDAP search filter format. These search filters use one of the following formats <filter>=(<attribute><operator><value>) or (<operator><filter1><filter2>). For example: "(&(objectCategory=person)(objectClass=user)(!cn=andy))"- All user objects but "andy".
Click on the Fetch Users button to import users from the active directory or LDAP.
When the list of existing users is displayed select the user(s) to be added, assign roles and click on Add Users to add the users.
In the new Import Users tab from the pop-up window select the users that you wish to add from the drop-down list.
Assign a role - Operator,User or Administrator to each of the users.
Click on the Add User button to import the user to SQLDBManager Plus or click on Add Users And Configure Another to add more users.
You can edit User Profiles from the list of users.
Delete a user
In Admin page, click User Administration under SQLDBManager Plus Server Settings.
Select the user(s) to be deleted.
Click Delete
You can create User Groups in SQLDBManager Plus with roles assigned to users or import user groups from Active Directory or LDAP.
Add new user groups to SQLDBManager Plus
In Admin page, click User Administration under SQLDBManager Plus Server Settings.
Click the User Groups tab. This lists down the User Groups in SQLDBManager Plus.
To add a new user group, click Add new. This opens the 'New User Group' screen.
Specify a User Group name.
Choose the users to be added to the group.
Select the monitor group to which the new users must be granted previleges.
Click Create User Group. The new user groups will be displayed in the User Groups table.
Importing user groups from active directory or LDAP
Users in the groups imported from the Active Directory or LDAP can login into SQLDBManager Plus using their Active Directory/LDAP credentials. Since user authentication is done in the Domain Controller all the account policy regulations of the company/domain is automatically inherited to SQLDBManager Plus credentials also.
In Admin page, click User Administration under SQLDBManager Plus Server Settings.
Click the User Groups tab.
Click the Import User Groups from Active Directory / LDAP link under the list of user profile
Select a domain name from the drop-down list.
The users in groups imported from Active Directory\LDAP will be associated automatically to that particular usergroup during login.
For Active Directory Users, the admin can import their group and use this feature in permissions tab (Create a new user account if the user logs in with domain authentication.)
Adding a New Domain
You can select an already added domain from the drop-down list or add a new domain. You can also edit the existing Domain controller settings in the same manner.
Select the Add New Domain option from the Domain Name drop-down list.
Enter the following details:
Domain Name: Name of the domain from where the users need to be imported.
Domain Controller: The hostname or the IP address of the DNS server for the domain.Domain Port: The port of the DNS server.
Authentication Type: LDAP or Active Directory.
Username and Password: The active directory username of the domain user should be provided in DOMAIN\username format. The LDAP user name should be provided in cn=user,dc=domain,dc=name format.
Search Filter: To filter out search result you can use characters followed by * as well as the role criterion in LDAP search filter format. These search filters use one of the following formats <filter>=(<attribute><operator><value>) or (<operator><filter1><filter2>). For example: "(&(objectCategory=person)(objectClass=user)(!cn=andy))"- All user objects but "andy".
Click on the Fetch User Groups button to import user groups from the active directory or LDAP.
When the list of existing users is displayed select the user(s) to be added, assign roles and click on Add User Groups to add the users.
You can also edit User Profiles from the list of users.
Delete a user group
In Admin page, click User Administration under SQLDBManager Plus Server Settings.
Click the User Groups tab.
Select the user groups to be deleted.
Click Delete.
Using the Permissions options, you can allow Operators to manage / unmanage
monitors, reset the status of monitors, edit display names and also to execute actions. Otherwise, the admin user has permission to perform these activities.
Also, permission can be given to Admin or operator to use the Telnet client of the server monitor, if the server was added in Telnet & SSH mode. AS400 Permissions allow you to permit Operators to execute AS400 Admin activities.
This is for Operator only. Using View option, you can define how to represent your subgroup in the webclient.You can either show the associated subgroups directly in the home tab itself or from the corresponding top level Monitor Group.
To enhance Web Client security, Account Policies can be configured. You can define the number of continuous failed login attempts to lock user account and Idle session timeout. You can enforce single user session and strong password rules.
Password cannot be same/part of your Login name
Password length should not be less than 8 character
Password length should not be greater than 255 character
Password should contain atleast 1 numeric character
Password should contain atleast 1 special character
Password should contain both uppercase and lowercase character
Password should not be same as your last 4 password(s)
You can import users and perform role configuration for LDAP users and groups in SQLDBManager Plus. Users and groups are fetched into SQLDBManager Plus from different domains, based on the entry in the authentication.conf file found in the following location. For LDAP configuration, you can edit the ldapauthentication.conf file found in the location: ManageEngine/SQLDBManagerPlus5/conf.
Ldap Configuration
ldap.group.commonNameAttribute=cn
ldap.group.primaryAttribute=cn
ldap.group.displayNameAttribute=cn
ldap.group.objectCategory=group
ldap.group.objectClass=posixGroup;groupOfNames
ldap.group.memberAttribute=member;memberUid
ldap.group.memberofAttribute=
ldap.group.groupTokenAttribute=gidNumber
ldap.user.commonNameAttribute=cn
ldap.user.primaryAttribute=uid
ldap.user.displayNameAttribute=cn
ldap.user.objectCategory=person
ldap.user.objectClass=person;posixAccount
ldap.user.memberofAttribute=
ldap.user.groupidAttribute=gidNumber
Active Directory Configuration
ad.group.commonNameAttribute=cn
ad.group.primaryAttribute=sAMAccountName
ad.group.displayNameAttribute=cn
ad.group.objectCategory=group
ad.group.objectClass=group
ad.group.memberAttribute=member
ad.group.memberofAttribute=memberOf
ad.group.groupTokenAttribute=primaryGroupToken
ad.user.commonNameAttribute=cn
ad.user.primaryAttribute=sAMAccountName
ad.user.displayNameAttribute=displayname
ad.user.objectCategory=person
ad.user.objectClass=
ad.user.memberofAttribute=memberOf
ad.user.groupidAttribute=primaryGroupID
Note If you have changes in LdapConfiguration.conf and later want to retain the initial configuration, simply rename the file (for example, rename it to LdapConfiguration_old.conf) or move the file to different location and restart SQLDBManager Plus. |
Configure SMS Server |
Add-on / Product Settings |