Working with Permission Profiles

A permission profile is a predefined set of permissions that you assign to administrators in a Multi-Domain Security Management environment. This lets you manage complex, granular permissions for many different administrators with one definition.

There are two types of permission profiles:

  • Multi-Domain permission profiles - Defines administrator permissions for the full Multi-Domain Security Management environment.

  • Domain permission profiles - Defines the permission set per Domain

Predefined Multi-Domain Permission Profiles

Multi-Domain Security Management includes predefined Multi-Domain and Domain permission profiles that are ready to use. You cannot delete or change these profiles. You can create custom permission profiles as necessary for your environment.

These are the predefined Multi-Domain permission profiles available in this release. In the Permissions Profile view, double-click each profile to see the permissions it includes:

Permission Profile

Permissions

Multi-Domain Superuser

Manage all elements of the Multi-Domain Security Management environment, including: Multi-Domain Servers, Multi-Domain Log Servers, Domains, Domain Management ServersClosed Virtual Security Management Server that manages Security Gateways for one Domain, as part of a Multi-Domain Security Management environment. Acronym: DMS., Global Policies, administrators and permission profiles. Multi-Domain Superusers manage all Domain objects, including Security Gateways, Policies, rules, networks and other objects.

Domain Superuser

Manage all Domains, Domain Management Servers, Domain networks, global objects, and global configurations. They manage Domain objects, including Security Gateways, Policies, rules, networks and other objects.

Domain Superusers can create and manage other administrators, manage other administrators' sessions, and manage permission profiles at the same or lower levels. Domain Superusers cannot create or change the settings for Multi-Domain Servers or Multi-Domain Log Servers.

Global Manager

Manage Global Domains, global configurations, global rules, and global assignments. Global Managers can manage Domains, but not add or delete domains or manage Multi-Domain Servers. Global managers can manage administrators with equal or lower permissions.

Global Managers can create new global assignments and can assign Global Policies to Domains that they have permissions to manage.

Domain-Level permissions are based on the assigned Domain permission profile.

Domain Manager

Manage Domain Policies, networks and objects based on their permission profile. Domain Managers can manage administrators with equal or lower permissions.

Domain Managers can reassign Global Policies to Domains that they have permissions to manage. They cannot create new global assignments.

Domain-Level permissions are based on the assigned Domain permission profile.

Domain Level Only

Manage Domain Policies, networks and objects based on their permission profile. These administrators cannot manage the Multi-Domain Security Management system or its configuration settings, or login to the Multi-Domain Servers.

Domain-Level permissions are based on the assigned Domain permission profile.

Pre-Defined Domain Permission Profiles

When you assign an administrator to Domain, you must also assign a Domain Permission Profile. You can assign a predefined Permission Profile or a custom Permission Profile for this administrator.

Permission Profile

Permissions

Read/Write

Read and write permissions for all Domain settings and data without session management or DLP confidential data. The Read/Write option lets the administrator see and configure an item.

Read Only

Read only permissions for all Domain data. Read Only lets the administrator see an item, but not change it.

Working with Multi-Domain Permission Profiles

Use this procedure to create or change customized Multi-Domain permission profiles. Only administrators with Superuser permissions can do this.

Multi-Domain Permission Profile Parameters

Creating Custom Domain Permissions

Customized Domain permission profiles are a set of granular permissions for Domain level activities in SmartConsole.

To configure custom permission profiles:

  1. In the Permission Profiles window, click New Domain Permission Profile.

    The New Domain Permission Profile window opens.

  2. Configure read/write permissions for each Software BladeClosed Specific security solution (module): (1) On a Security Gateway, each Software Blade inspects specific characteristics of the traffic (2) On a Management Server, each Software Blade enables different management capabilities., feature, resource, and the API in these categories as necessary:

    To prevent administrators from working with an item, clear its option.

Notes:

  • You cannot prevent administrators from seeing some resources. You cannot change their options.

  • Some resources do not have Read or Write options. You can only select or clear them.