When you create an authorization profile, you must associate the authorization profile with user groups, roles, and objects. This association controls the access given to specific user groups, roles, or objects. Users who are members of the Administrators group can create authorization profiles.
Before you begin
- You must have access to the user groups, roles and permissions, and objects to include in the authorization profile.
- User groups and roles must be available to select during creation of the authorization profile. Because objects are not a required component, you can create an authorization profile without them, and specify the objects at a later time.
- Before you can specify infrastructure objects, you must have added the infrastructure servers to the Presentation Server, as described in Registering the data providers with the Presentation Server.
To create an authorization profile
- Log on to the Operations Management Console, and in the navigation pane, select Administration > Authorization Profiles.
- On the Authorization Profiles page, select the page action menu Create, and select
- On the Create Profile page, enter a name for the new authorization profile.
- Specify the user groups for your realms.
If your system comprises multiple realms, you can specify user groups from more than one realm.
- Select the User Groups tab.
- Click + Add to open the Search for User Groups box.
- Select the user groups to include from the realm, and click OK.
- (Optional) Specify groups from another realm.
- Specify the roles:
- Select the Roles tab, and select + Add.
- Select the roles to include, and click OK.
The list of roles includes default roles and any that you created.
- To specify the objects that users in this profile can access, select the Objects tab, and perform the following steps. Otherwise, skip to the next step.
- To specify objects that users can access in the TrueSight Presentation Server, select TrueSight Presentation, and specify an available type and source. To specify individual objects, select the action menu and select available objects from the list.
- To specify objects that users can access in TrueSight Infrastructure Management, select TrueSight Infrastructure, and specify an available type and source. To specify individual objects, select the action menu and select available objects from the list.
- Click Save.
- To grant unrestricted access to all objects, select the Objects tab, and perform the following steps:
- Select the Associated Objects action menu.
- Select Edit, and in the Unrestricted Access for Types box, select one or more options.
- Click Save.
Managing authorization profiles
Editing and deleting authorization profiles
PATROL Agent ACLs