Mapping LDAP groups to user roles for the Console
If your LDAP groups correspond to the user roles in the BMC Real End User Experience Monitoring product, you can map those groups to the user roles. Mapping LDAP groups to user roles enables you to manage your user permissions for the BMC Application Performance Management Console from your LDAP server.
You can map multiple groups to a single user role, but you cannot map a group to more than one user role. You can modify the mapping by removing or adding groups to a user role.
Before you begin
- You must have Configured LDAP authentication for the Console.
- You must know the names of the LDAP groups.
- You must be logged on to the Console with one of the following user roles:- (BMC Real End User Experience Monitoring On-premises) Administrator-level access or higher
- (BMC Real End User Experience Monitoring SaaS) Access Manager-level access or higher
 
To map an LDAP group to a user role
- On the BMC Application Performance Management Console, select System Access > LDAP > Role Mapping.
 The Role Mapping page lists the system user roles and their corresponding LDAP groups.
- Select the Edit Mapping menu option for the corresponding user role.
- On the Edit Groups of Role page, enter the name of an LDAP group, and click Add.
- Repeat step 3, as necessary, for this user role, and click Save.
 The specified groups appear with the corresponding user role.
- Repeat steps 2–4, as necessary, for each user role.
To remove an LDAP group from a user role mapping
- On the BMC Application Performance Management Console, select System Access > LDAP > Role Mapping.
- Select the Edit Mapping menu option for the corresponding user role.
- Click the X to the right of each LDAP group to remove from the selected user role, and click Save.
 If you accidentally delete a mapping, click Cancel to start over.
Related topics
Configuring-LDAP-authentication-for-the-Console
Selecting-an-account-management-model
Tip: For faster searching, add an asterisk to the end of your partial query. Example: cert*
