Managing access control

From the TrueSight console and TrueSight Capacity Optimization consoles, you can view the user information, but all modifications to user information must be performed in Remedy Single Sign-On. Any specific user permissions or access changes must be performed in the TrueSight and TrueSight Capacity Optimization consoles.


Note

If you have integrated TrueSight Capacity Optimization with Remedy Single Sign-On, users of other BMC products that have been integrated with Remedy SSO can access TrueSight Capacity Optimization. For information about managing users in Remedy Single Sign-On, see Remedy Single Sign-On product documentation .




To configure access control, you must complete the following steps:

StepTaskResource
1Set up users and user groups in Remedy Single Sign-On.

Configuring users and user groups

2

For features that are available in the TrueSight Capacity Optimization console:

Configure user roles with the external names.

Information: For the default user groups in Remedy SSO, user roles in the TrueSight Capacity Optimization console are already configured.

Managing roles

Adding and managing access groups

For features that are available in the TrueSight console:

  • Create authorization profiles.
  • Configure user roles with the external names.

Configuring authorization profiles

Managing roles

Adding and managing access groups

Information

If you use the default user groups, no additional mapping is required in TrueSight Capacity Optimization and TrueSight console. Only if you add a new user group in Remedy SSO, you need to map it with a user role in TrueSight Capacity Optimization.

To configure authorization profiles in TrueSight Presentation Server

  1. Log in to the TrueSight console as a Super Admin.
  2. Navigate to Administration>Authorization Profiles.
  3. Create a new authorization profile or edit an existing authorization profile to associate the user groups.
  4. Select the tenant that you configured in Remedy Single Sign-On for LOCAL users and select Edit under User Groups
  5. Click Add and select the LOCAL user group from the list of user groups, and Save.
  6. (Optional) Select a role from the list roles.
  7. (Optional) Select an object from the list of object.
  8. Select OK and then Save.
  9. Select Yes to confirm changes to the authorization profile.
  10. Log out of the TrueSight console.
  11. Log in to the TrueSight console as a LOCAL user.

For more information, see Managing authorization profiles .

Administering multiple tenants or customers using RBAC

TrueSight Capacity Optimization administrators can use the TrueSight Capacity Optimization RBAC system to manage multiple tenants or customers by assigning specific activities and specific access groups to specific roles. If necessary, TrueSight Capacity Optimization administrators can create roles and activities to tailor the RBAC system to suit your needs.

However, when you are managing multiple tenants or customers, the following apply to your TrueSight Capacity Optimization deployment:

  • All of the data for the TrueSight Capacity Optimization deployment is stored in a single database, and TrueSight Capacity Optimization implements security at the user authentication level.
  • The TrueSight Capacity Optimization administrator manages the following entities:
    • Data connectors
    • Global objects such as time filters and entity filters
    • All collected data until it is moved into the domain hierarchy
  • The TrueSight Capacity Optimization administrator retains all user, role, and access group administration functions. Individual customers cannot have their own tenant administrators.

Related topics

Configuring user authentication

Security considerations for TrueSight Capacity Optimization

Was this page helpful? Yes No Submitting... Thank you

Comments