
You can use the Diagnostics feature to view the roles that are assigned to a user and the features that are
enabled or disabled for each of those roles. For more information about the Diagnostics feature, see User
Security Diagnostics on page 286.
Restrict Roles to Device Groups
When you create a role, you can restrict the role to device groups and limit the permission set to specic device
management features, such as conguring devices, running discoveries, and updating the device rmware. To
limit the permission set to device groups from the Create Role wizard, you must select the Device Groups option
from the Restriction type list on the Specify permission settings page. Then you can enable or disable each
device management feature. For instructions on creating roles, see Create Roles on page 281.
After you create a role that is limited to the device management features, you can assign the role to a user.
During the process of assigning the role to a user, you must specify the device groups to which the role is
restricted. The user can access the device management features that are enabled for the role only on the
devices that are members of the specied device groups. The user cannot access the device management
features on devices that are not members of the specied device groups. For instructions on assigning roles, see
Assign Roles to Users on page 284.
Create Roles
If you have permission to manage users, you can create roles by using the Create Role wizard.
To create roles, perform the following steps:
1. In the Application Management navigation pane, right-click Roles, and then select Create. The Create Role
wizard starts.
NOTE: You can assign more than one role to a user. The permission sets for roles are cumulative. If you
assign one role to a user, you can grant additional permissions to that user by assigning another role that
has a dierent permission set. Users never lose permissions when multiple roles are assigned to them. For
example, assume that Role A enables permission to update the device rmware and Role B disables
permission to update the device rmware. If you assign Role A to a user, the user can update the device
rmware. If you then assign Role B to the user, the user retains permission to update the device rmware.
2. On the Specify permission settings page, select one of the following options from the Restriction type list:
●
None: The permission set for this role applies to all areas of HP Web Jetadmin.
●
Device Groups: The permission set for this role is limited to the device management features.
NOTE: If the Device Groups option is selected, you must also specify the device groups to which the
role is restricted when you assign the role to a user. For instructions on assigning roles, see Assign
Roles to Users on page 284.
3. Select the checkbox next to each permission that you want to enable for the role, and then click the Next
button.
NOTE: You must enable at least one permission.
4. On the Specify role name page, enter a name for the role in the Role name box, and then click the Next
button.
NOTE: Each role must have a unique name.
5. On the Conrm page, verify that the information is correct, and then click the Create Role button.
ENWW User Security 281
Komentáře k této Příručce