Creating an LDAP-managed account
To authenticate through an LDAP server, you must map groups on your Lightweight Directory Access Protocol (LDAP) server to specific
roles.To add a hybrid LDAP account (LDAP authentication only)
This procedure adds an Operator account that is authenticated remotely via LDAP.
- In a component, point to Administration > General Settings, and then click Accounts & LDAP management.
- Select the Accounts view.
- On the Action menu, click Add an account.
- In the User Name box, enter the name for the account — for example, MyOperator.
- In the Authentication list, select LDAP.
- In the Role list, select Operator.
- Click Save.
To add a full LDAP account (LDAP authentication and authorization)
In the LDAP database, suppose that the user name is listed as MyUser and is a member of a group called Admins. This LDAP group is mapped to the Administrator role on this
device. This procedure gives access to the user as an Observer (so you must override the mapped role).- In a component, point to Administration > General Settings, click Accounts & LDAP management, and switch to the Accounts view.
- On the Action menu, click Add an account.
- In the Username text box, type MyObserver.
- Select the Authentication type LDAP.
- Select Override role mapping and then select Observer.
- Click Save.
To set the "catch-all" role-mapping
This procedure sets a default level of access to your BMC Real End User Experience Monitoring system for LDAP groups that do not have a specific role-mapping rule.
- In a component, point to Administration > General Settings, click Accounts & LDAP management, and switch to the Role mapping view.
- On the Action menu, click Add/Edit.
- In the All others row, select a catch-all role for LDAP groups that are not specifically identified with a BMC Real End User Experience Monitoring role, or select No access.
- Click Save.
Related topics
Creating-a-local-account
Configuring-authentication-through-LDAP
Configuring-authorization-through-LDAP
Tip: For faster searching, add an asterisk to the end of your partial query. Example: cert*