LDAP Feature for the Remote Console Switch : Configuring Group Objects

Configuring Group Objects
Access control is applied to a specific Active Directory user account by including that user in the membership of a Group in the Group Container. The Group membership must also contain the objects representing the Remote Console Switch(es) and the SIP(s) the user is allowed to access. The level of access granted is determined by the value of a specific attribute in the Group object (Standard Schema) or Association Object (Extended Schema). There are three permission levels available. In increasing order of access they are, "KVM User", "KVM User Admin" and, the most powerful level, "KVM Appliance Admin."
NOTE:
Table 9 2. LDAP (Group Attribute Authorization)
Allowed to preempt another Appliance Admin or a User Admin. Permission must be configured for each target device by including the TD in the appropriate Group object in the Directory.
Allowed to preempt another User Admin. Permission must be configured for each target device by including the target device in the appropriate Group object in the Directory.
Configure network parameters and global settings
Yes – Permission must be configured for each appliance by including the appliance in the appropriate Group object in the Directory.
Yes – Permission must be configured for each appliance by including the appliance in the appropriate Group object in the Directory.
Yes – Permission must be configured for each appliance by including the appliance in the appropriate Group object in the Directory.
Yes – Permission must be configured for each appliance by including the appliance in the appropriate Group object in the Directory.
Yes – Permission must be configured for each appliance by including the appliance in the appropriate Group object in the Directory.
Yes – Permission must be configured for each appliance by including the appliance in the appropriate Group object in the Directory.
Yes – Permission must be configured for each appliance by including the appliance in the appropriate Group object in the Directory.
Yes – Permission must be configured for each appliance by including the appliance in the appropriate Group object in the Directory.
Yes – Permission must be configured for each appliance by including the appliance in the appropriate Group object in the Directory.
Yes, if configured by Administrator
Permission must be configured for each target device by including the TD in the appropriate Group object in the Directory.
An AD user account must be configured to receive appliance administrator permission before that account will be allowed to modify any of the fields in the Authentication Panel. In particular, only an appliance administrator is allowed to modify the Authentication Settings.