Users and Role Based Access Controls

 

To add users as an admin:

  • Select Settings->Users.
  • Under the User Management tab, click on the Add User button in the right corner.
  • Enter the essential details of the user, including Name, Username, email, and password. You can enable or disable the login for this particular user. Set Yes to enable the login. Enable the TOTP login for the user to add an extra layer of security.
  • Finally, Assign the appropriate role for the user.
  • DDI provides only two roles: Admin and Operator. The Admin role has unrestricted access, while the Operator role has limited access, which can be extended by granting specific permissions for each cluster or zone as needed.
  • Click Save.
  • Provide the Username, Password, and URL for the other users you've added. Make sure they login using the URL from their web browser.
  • Once they login they'll be prompted to reset their password and log into the DDI Central application.

Note: It is mandatory for every user logging into DDI Central for the first time to reset their password and set their email to an active email ID. By default, DDI Central comes with a dummy username, password, and email as placeholders.

If users, in their haste to set up the environment, forget to reset these credentials, they will not be able to access the application.



Note:

Users with the Operator role do not have permission to configure DHCP failover on the server. Only users with the Admin role can create, update, or delete failover configurations.

Enabling Two-factor authentication for the users

DDI Central enhances user account security by mandating two-factor authentication (2FA) for all users associated with your organization. This additional security layer requires verification through a time-sensitive code generated by a compatible mobile authenticator application. The following steps outline the 2FA process.

  1. Users need a mobile device capable of running a TOTP-enabled authenticator mobile app.
  2. DDI Central is compatible with various mobile authenticator apps, including Google Authenticator, Zoho's OneAuth, Authy, and others.
  3. Install your chosen authenticator app on your smartphone.
  4. Link DDI Central to the authenticator app either by scanning the QR secret code displayed on the DDI Central login page or by entering the code manually. This is a one-time process.

  5. On subsequent logins, enter the TOTP displayed in your authenticator app. The OTP adds an extra layer of security and can be generated without an internet connection.
  6. Upon first accessing DDI Central, all users including the Admin who managed the installation process will need to reset their password.

This two-factor authentication approach ensures that access to your DDI Central account is secure, combining something the user knows (their password) with something they have (a TOTP from the authenticator app).

User permissions

Admin canOperator can
Create, update, and delete user-
Add, update, and delete zonesUpdate zone if operator has zone permission
Create update and delete cluster-
Giving cluster and zone permission to the operator-
Add, update, and delete servers-
Add SMTP details-
Able to see login and logout details of the user-
Able to see DHCP and DNS audit report-
Reset client credentialsReset client credentials
Enable TOTP for an user-
Delete TOTP device-
Add, update, and delete records in zoneAdd, update, and delete records in zone if the operator has zone permission
Add, update, and delete named optionsAdd, update, and delete named options if the operator has cluster permission
Add, update and delete dhcp optionsAdd, update and delete dhcp options if operator has cluster permission
Add, update, and delete custom optionsAdd, update, and delete custom options if the operator has cluster permission
Add, update, and delete subnet, shared network, client class, host, host group and vlanAdd, update and delete subnets, shared network, client classes, host, host group and vlan if the operator has cluster permission
Add, update and delete supernetAdd, update and delete supernet if operator has cluster permission
Add, update, and delete failover configurationsAdd, update, and delete failover if the operator has cluster permission
Enable, add, update, and delete named viewsupdate named_view if operator has cluster permission
Add, update and delete DHCP ZoneAdd, update, and delete DHCP Zone if operator has cluster permission
Add, update, and delete records in viewsUpdate view if operator has zone permission

Note:

The Superadmin, the first mover, or the first user who installs the product must replace the default email address, "ddiadmin@manageengine.com," with their preferred or official email address under their user profile within the DDI Central app immediately after logging in. This is essential because DDI Central sends notifications only via email. Registering their email address ensures they receive timely notifications.

The Superadmin steps into DDI Central with the default username "admin" and password "admin" during the installation process. Therefore, it is mandatory for this user to not avoid DDI Central's prompts to reset their password to continue accessing the app.

If TOTP authentication is configured instead of SAML, the TOTP login session is valid for only two minutes. If the login is not attempted within this time, the user must re-enter their login credentials to avoid potential attacks.


Note:

When a user has been added and granted an admin role in the application, a small supervisor icon appears next to the username in the User Management section.

Operator Plus

Compared to the standard Operator role, which grants access at the module level only — DNS, DHCP, or both, with no further scoping — the Operator Plus role provides object-level control within each module. Access can be granted or restricted for individual domains, subnets, views, policies, and other DNS and DHCP objects, rather than the module as a whole.

Permissions for DNS, DHCP, Analytics, Audit Trails, and Servers are configured independently per cluster. A complete permission configuration can also be saved as a template and reused when provisioning additional users with similar access requirements.

Access levels

LevelWhat it means
NoneHidden from the user entirely.
ViewRead-only.
ManageCreate, edit, and update.
Manage & ConfigureFull control, including delete.

A few resources use a shorter scale — DNS Configuration, DHCP Configuration, and DNS Records cap at Manage; Analytics and Audit Trails offer only None/View. Servers uses its own four tiers with different labels: None, View, Add & Edit, and Add, Edit & Delete.

Where access can be set to All or Select Specific, choosing Select Specific opens a picker to name exactly which resources the permission applies to.

DNS permissions

You can set granular access for Domains, DNS Views, DNS Records, and DNS Configuration — each independently, scoped to All or specific items as needed.

  • DNS Views is scoped by your Domains access — a user can't be granted views under a domain they don't already have access to.
  • DNS Records sets a blanket record access level, which you can override for individual record types underneath if a user needs different access per record type.

DHCP permissions

Subnets, static subnets, supernets, multicast subnets, and hosts all follow the same pattern — granular access applied to all resources under the specific cluster.

  • Shared Networks access isn't set directly — it follows the individual subnets in the network. If a user has Manage access to one subnet in a shared network but no access to another subnet grouped with it, they can still view that second subnet, but not manage or configure it. The same applies to host groups.
  • Policies & Client Classes are two independent permissions bundled under one section — Policies apply to Windows clusters, Client Classes to Linux clusters — and can be set to different access levels from each other.
  • DHCP Configuration covers failover, filters, and DHCP options as one setting — View or Manage only.

Analytics, Audit & Servers

  • Analytics and Audit Trails (DNS and DHCP, set separately) are simple None/View toggles.
  • Servers uses None, View, Add & Edit, and Add, Edit & Delete instead of Manage/Manage & Configure, but follows the same escalating logic.

Supplementary User Roles in DDI Central

DDI Central also has supplementary user roles with different visibility and permissions for accessing network resources of your organization's network. This way, the administrators can add these roles to have more visibility on the network activities and also limit their access to a certain boundary.

They are,

  1. Guest
  2. Auditor

Guest

Guest user type allows the user only to view and monitor network activities in the DNS and DHCP clusters, and they won't have access to configure the settings and policies. This helps the administrators add more individual users to have visibility on the network services and review them.

Auditor

The Auditor role enables the user to view only the audits of the networks services in the DNS and DHCP clusters, and they won't have access to view the network activities, and can't configure the settings. This helps in reviewing the actions executed on each of the clusters added in DDI Central.

Note:

The Guest role is available in both Professional and Essential editions, whereas the Auditor user role is only available in the Professional edition.

Both these user roles help with the auditing and compliance purposes. Higher officials and supervisors can effortlessly review the network activities and audit logs in the respective DDI clusters, by adding them as Guest or Auditor in the DDI Central application.

Enabling other stakeholders to review prevents errors and misinformation in the network data, and administrators can be alerted for troubleshooting the network error. This also helps provide an all around visibility to other teams like the compliance team to have verification over the network data in case anything is misplaced or missed.

Configuring Role Based Access Controls (RBAC) for DNS

DNS domains in the network can be access granted to individuals of the organization through DDI Central. Admins can grant access to selected users for specific DNS domains in the network.

To grant access to users in the network:

  1. Click through Settings>Users>Add User.
  2. Provide the details in the following fields:
  • NAME: Provide the name of the individual in the network.
  • USERNAME: Provide their username assigned in the network.
  • EMAIL: Provide the network admin's email ID.
  • PASSWORD: Provide the password for configuration.
  • TOTP: Enable TOTP for Two step verification before granting access to the domains.
  • ROLE: Select the role you want to assign to the individual. There are 4 different role options, and only Operator and Guest roles can be granted access to the domains.
  • CLUSTERS: Select the cluster from which the individuals gets access granted to the domains.
  • TYPE: Select from which network service's resources need access granted.

The IPAM Permissions field allows network administrators to selectively grant individuals access to view the IPAM Tower View data of the cluster. The View type allows users to view the data, while the Restrict type completely prevents users from accessing the IPAM data.

  • Under the DNS configuration section we have MONITOR PERMISSIONS, where you can prevent the user for accessing the monitors with RESTRICT option, or you can just let them view the monitors in the network with VIEW option, or you can allow them to edit the monitors with the EDIT option.
  • In the DNS domains section, you can select ALL for granting access to all the domains in the network, or select SELECT ZONES option for granting access to specific zones in the selected cluster.
  • Click on +Add Cluster Permissions option to save the configurations, and click on Save to add the user with the access permissions in the network.
  • Configuring Role Based Access Control (RBAC) for DHCP

    DHCP subnets, supernets, and hosts in your organizations' servers can now be assigned to individuals in the network based on their roles. Admins can grant access to selected users for specific subnets, supernets, and hosts in the network.

    To grant access to users in the network:

    1. Click through Settings>Users>Add User.
    2. Provide the details in the following fields:
    • NAME: Provide the name of the individual in the network.
    • USERNAME: Provide their username assigned in the network.
    • EMAIL: Provide the network admin's email ID.
    • PASSWORD: Provide the password for configuration.
    • TOTP: Enable TOTP for Two step verification before granting access to subnets, supernets, or hosts.
    • ROLE: Select the role you want to assign to the individual. There are 4 different role options, and only Operator and Guest roles can be granted access to subnets, supernets, or hosts.
    • CLUSTERS: Select the cluster from which monitors and domains need access granted for the individuals.
    • TYPE: Select from which network service's resources need access granted.

    The IPAM Permissions field allows network administrators to selectively grant individuals access to view the IPAM Tower View data of the cluster. The View type allows users to view the data, while the Restrict type completely prevents users from accessing the IPAM data.

  • Select the supernet you want to grant access for the users in the Select Supernets field.
  • When the supernet is selected, two new options gets displayed for the SUPERNET PERMISSION:
    • MANAGE - This option can only allow the user to manage the existing subnets in the selected supernet.
    • MANAGE AND CONFIGURE - This option can allow the user the both manage the subnets and also create new subnets within the selected supernet.
  • Below that, you can select subnets for access granting, where you can select all the subnets in the network by clicking on ALL, or select specific subnets by clicking on SELECT SUBNETS.
  • Finally, you can select the hosts for access granting, where admins can select ALL for managing all the hosts in the cluster, or select ASSIGNED SUBNETS or ASSIGNED SUPERNETSfor managing hosts under the assigned subnets or supernets, accessible by the user.
  • Click on +Add Cluster Permissions option to save the configurations, and click on Save to add the user with the access permissions in the network.
  • User Audits

    The User Audit tab can be accessed by selecting the Audit menu from the left menu bar. The User audit tab helps you monitor your users' login activities by capturing the username, date, and timestamp of the latest login activities.