Access to Cloud Manager requires a Cloud Manager user account. Through the account, a user receives rights to perform various roles in the Cloud Manager system, in an organization, or in both. Rights can also be assigned to user groups to enable all members of the group to perform specific roles.
You can create users and groups by manually entering information or by importing information from your LDAP authentication source.
On the main navigation bar, click
, then click (in the list).or
On the main navigation bar, click
, then click the tab.On the
tab, click to display the Create User dialog box.Provide the following details to define the user:
Full Name: Specify the user’s full name as you want it to appear in NetIQ Cloud Manager.
E-Mail Address: Specify the user’s e-mail address as defined in their LDAP authentication account. If necessary, you can specify more than one address; use commas to separate addresses.
The e-mail address enables the Cloud Manager system to send messages (tasks, notifications, and so forth) to the user as needed.
Phone Number: This field is optional. Specify a contact number if desired.
Select the user’s scope:
Organization: An organization scope enables the user to perform roles within a specific organization. The roles are Approver, Build Administrator, Business Group Viewer, Business Service Owner, Organization Manager, Sales Manager, and Sponsor.
To give the user an organization scope, select
, then select the organization in which to place the user.System: A system scope enables the user to administer the Cloud Manager system. The roles are Approver, Build Administrator, Catalog Manager, Cloud Administrator, and System View. In addition, a System user can be given any of the organization roles.
NOTE:System scope also implies the Zone Administrator role, though it is not explicitly listed. Instead, specific zones are associated to these users, making the Zone Administrator role implicit.
(Organization user only) If you want the user to always be able to view business service costs regardless of the
setting for a business group, select .An organization’s or business group’s
setting can be set to or . The purpose of the setting is to ensure that business service costs are always visible to the user even if the setting is set to .For example, you might want to select this option for users who are Sponsors. This ensures that the users can always see costs even if the organization or business group is set to hide costs.
(System user only) Assign system-level roles to the user.
The system-level roles are Approver, Build Administrator, Catalog Manager, Cloud Administrator, and System View. These roles can be assigned only to System users.
NOTE:System scope also implies the Zone Administrator role, though it is not explicitly listed. Instead, specific zones are associated to these users, making the Zone Administrator role implicit.
To assign the Approver, Build Administrator, Catalog Manager, or Cloud Administrator role, click the
tab, click , select the desired roles, then click .To assign the Zone Administrator role, click the
tab, click , select the desired zone, then click .Assign organization-level roles to the user.
The organization-level roles are Approver, Build Administrator, Business Group Viewer, Business Service Owner, Organization Manager, Sales Manager, and Sponsor. The Approver, System View, and Build Administrator roles can be assigned only to System users. The Sales Manager role can be assigned only to Organization users. The other roles can be assigned to both System users and Organization users.
Several of the roles can be assigned at the organization, business group, or business service level. For example, you can make a user a Sponsor for a business group, in which case the user can approve requests for business services from that business group only. Or, you can make the user a Sponsor for the organization, in which case the user can approve requests for all business services in the organization.
Click the
tab to add a role at the organization level, click the tab to add a role at the business group level, or click the tab to add a role at the business service level.Click the role that you want to assign
For example, if you selected the
tab and you want to enable the user to create business services for the business group, click .Click
, select the object (organization, business group, or business service) to which you want the role to apply, then click to add it to the list.Ignore the
tab at this time.The Manually Creating User Groups and Importing User Groups from LDAP
tab lets you add users to groups. You must create the groups first. This task is discussed inWhen you have finished assigning roles to the user, click
.For more information about users and roles, see Section 11.0, Setting Up and Managing Users.
Rather than assign roles to individual users, you can create user groups and assign roles to the user groups. Users (and other user groups) that are added to a group inherit the group’s roles.
User group roles are cumulative. If you add a user to a group, the user retains its directly assigned roles and also gains the roles inherited from the group.
On the main navigation bar, click
, then click (in the list).or
On the main navigation bar, click
.Click the
tab, then click to display the Create User Group dialog box.Provide the following details to define the user group:
Full Name: Specify the group’s full name as you want it to appear in NetIQ Cloud Manager.
E-Mail Address: This field is optional. If you enter an e-mail address, any messages generated for the group’s roles are sent to the e-mail address. If you don’t enter an e-mail address, the messages are sent to the group members’ addresses.
Select the group’s scope:
Organization: An organization scope enables the group to be assigned roles within a specific organization. The roles are Business Group Viewer, Business Service Owner, Organization Manager, Sales Manager, and Sponsor.
To give the group an organization scope, select
, then select the organization in which to place the group.System: A system scope enables the group to be assigned roles for the Cloud Manager system. The roles are Approver, Build Administrator, Catalog Manager, Cloud Administrator, and System View. In addition, a System group can be given any of the organization roles.
NOTE:System scope also implies the Zone Administrator role, though it is not explicitly listed. Instead, specific zones are associated to these users, making the Zone Administrator role implicit.
(System user groups only) Assign system-level roles to the group.
The system-level roles are Approver, Build Administrator, Catalog Manager, Cloud Administrator, and System View. These roles can be assigned only to System user groups.
To assign the Approver, Build Administrator, Catalog Manager, or Cloud Administrator role, click the
tab, click , select the desired roles, then click .To assign the Zone Administrator role, click the
tab, click , select the desired zone, then click .Assign organization-level roles to the group.
The organization-level roles are Approver, Build Administrator, Business Group Viewer, Business Service Owner, Organization Manager, Sales Manager, and Sponsor. The Approver and Build Administrator roles can be assigned only to System user groups. The other roles can be assigned to both System and Organization user groups.
Several of the roles can be assigned at the organization, business group, or business service level. For example, you can make a user group a Sponsor for a business group, in which case the group members can approve requests for business services from that business group only. Or, you can make the user group a Sponsor for the organization, in which case the group members can approve requests for all business services in the organization.
Click the
tab to add a role at the organization level, click the tab to add a role at the business group level, or click the tab to add a role at the business service level.Click the role that you want to assign.
For example, if you selected the
tab and you want to enable the user group to create business services for the business group, click .Click
, select the object (organization, business group, or business service) to which you want the role to apply, then click to add it to the list.Add members to the group:
Click the
tab.Click
, then click to display the Add Members dialog box.Select the users and user groups you want to add to the group.
You can Shift-click and Ctrl-click to select multiple users and groups.
Click
to add the users and user groups to the Members list.When you have finished assigning roles and adding members, click
.For more information about user groups and roles, see Section 11.0, Setting Up and Managing Users.
You can create users by importing information from your LDAP authentication source. You can import users as System or Organization users. After you import a user, you can assign roles to the user.
On the main navigation bar, click
, then click (in the list).or
On the main navigation bar, click
.If you want to import Organization users, click the
tab, select the target organization for the import, click to display the Edit Organization dialog box, then click (located above the list on the tab).or
If you want to import System users, click
(on the main navigation bar) to display the System Configuration dialog box, click , click the tab, then click .Authenticate to the LDAP directory:
Click the
tab.In the
section, fill in the following fields:Host: Specify the FQDN (fully qualified domain name) or IP address of the host machine running the LDAP server. For example, ldap.mycompany.com or 123.45.67.8.
Port: Specify the TCP port (on the host machine) where the LDAP server is listening for LDAP connections. The standard port for non-SSL connections is 389. The standard port for SSL connections is 636.
Use SSL: If the Cloud Manager Application Server is configured for an SSL connection to the LDAP server, select this option to enable the secure connection.
In the
section, fill in the following fields:DN: Specify an account that has search rights to the directory location from which you want to import users. For example, cn=Administrator,cn=Users,dc=MyCompany,dc=com
Password: Specify the password for the account.
Password Confirm: Confirm the password for the account.
Click
.If the connection is successful, the Test Status is displayed as
. If the connection is not successful, validate the connection information and try again.Import users:
Click the
tab.Click
.When you click
, an new import entry is added to the list. You use the fields below the list to define the entry.In the DN field, use standard LDAP notation (ou=provo,dc=netiq,dc=com) to specify the distinguished name for the target container or object, then click .
If you specify a container, all users located within the container are imported. If you only want to import one user, specify the DN of the user object.
If you specified a container for import, select
.If you specified a container for import, select
if you want to import users located in its subcontainers.Click
.The imported users are added to the
list. Users are identified by the icon.When you have finished importing users, click
or to close the dialog box.Assign roles to the users:
On the main navigation bar, click
.Click the
tab, select the user to whom you want to assign roles, then click .(System user only) Assign system-level roles.
The system-level roles are Approver, Build Administrator, Catalog Manager, Cloud Administrator, and System View. These roles can be assigned only to System users.
NOTE:System scope also implies the Zone Administrator role, though it is not explicitly listed. Instead, specific zones are associated to these users, making the Zone Administrator role implicit.
To assign the Approver, Build Administrator, Catalog Manager, Cloud Administrator, or System View role, click the
tab, click , select the desired roles, then click .To assign the Zone Administrator role, click the
tab, click , select the desired zone, then click .Assign organization-level roles.
The organization-level roles are Approver, Build Administrator, Business Group Viewer, Business Service Owner, Organization Manager, Sales Manager, and Sponsor. The Approver and Build Administrator roles can be assigned only to System users. The Sales Manager role can be assigned only to Organization users. The other roles can be assigned to both System users and Organization users.
Several of the roles can be assigned at the organization, business group, or business service level. For example, you can make a user a Sponsor for a business group, in which case the user can approve requests for business services from that business group only. Or, you can make the user a Sponsor for the organization, in which case the user can approve requests for all business services in the organization.
Click the
tab to add a role at the organization level, click the tab to add a role at the business group level, or click the tab to add a role at the business service level.Click the role that you want to assign
For example, if you selected the
tab and you want to enable the user to create business services for the business group, click .Click
, select the object (organization, business group, or business service) to which you want the role to apply, then click to add it to the list.When you have finished assigning roles to the user, click
.For more information about users and roles, see Section 11.0, Setting Up and Managing Users.
You can create user groups by importing them from your LDAP authentication source. After you import a group, you can assign roles to the group.
An imported user group’s membership is maintained in the LDAP authentication source. Any users who are members of the user group in the LDAP source receive the roles that are assigned to the user group in Cloud Manager.
An imported user group’s members are not imported and do not display in the group’s
list. In addition, you cannot manually add users or user groups to an imported group.On the main navigation bar, click
, then click (in the list).or
On the main navigation bar, click
.If you want to import Organization user groups, click the
tab, select the target organization for the import, click to display the Edit Organization dialog box, then click (located above the list on the tab).or
If you want to import System user groups, click
(on the main navigation bar) to display the System Configuration dialog box, click , click the tab, then click .Authenticate to the LDAP directory:
Click the
tab.In the
section, fill in the following fields:Host: Specify the FQDN (fully qualified domain name) or IP address of the host machine running the LDAP server. For example, ldap.mycompany.com or 123.45.67.8.
Port: Specify the TCP port (on the host machine) where the LDAP server is listening for LDAP connections. The standard port for non-SSL connections is 389. The standard port for SSL connections is 636.
Use SSL: If the Cloud Manager Application Server is configured for an SSL connection to the LDAP server, select this option to enable the secure connection.
In the
section, fill in the following fields:User DN: Specify an account that has read rights to the directory location from which you want to import users. For example, cn=Administrator,cn=Users,dc=MyCompany,dc=com
Password: Specify the password for the account.
Password Confirm: Confirm the password for the account.
Click
.If the connection is successful, the Test Status is displayed as
. If the connection is not successful, validate the connection information try again.Import user groups:
Click the
tab.Click
.When you click
, an new import entry is added to the list. You use the fields below the list to define the entry.In the DN field, use standard LDAP notation (ou=provo,dc=netiq,dc=com) to specify the distinguished name for the target container or object, then click .
If you specify a container, all user groups located within the container are imported. If you only want to import one user group, specify the DN of the user group object.
If you specified a container for import, select
.If you specified a container for import, select
if you want to import user groups located in its subcontainers.Click
.The imported user groups are added to the
list. User groups are identified by the icon.When you have finished importing user groups, click
or to close the dialog box.Assign roles to the groups:
On the main navigation bar, click
.Click the
tab, select the user group to which you want to assign roles, then click .(System user groups only) Assign system-level roles.
The system-level roles are Approver, Build Administrator, Catalog Manager, Cloud Administrator, and System View. These roles can be assigned only to System user groups.
NOTE:System scope also implies the Zone Administrator role, though it is not explicitly listed. Instead, specific zones are associated to these user groups, making the Zone Administrator role implicit.
To assign the Approver, Build Administrator, Catalog Manager, System View, or Cloud Administrator role, click the
tab, click , select the desired roles, then click .To assign the Zone Administrator role, click the
tab, click , select the desired zone, then click .Assign organization-level roles.
The organization-level roles are Approver, Build Administrator, Business Group Viewer, Business Service Owner, Organization Manager, Sales Manager, and Sponsor. The Sales Manager can be assigned only to Organization user groups. The Approver and Build Administrator roles can be assigned only to System user groups. The other roles can be assigned to both System and Organization user groups.
Several of the roles can be assigned at the organization, business group, or business service level. For example, you can make a user group a Sponsor for a business group, in which case the group members can approve requests for business services from that business group only. Or, you can make the user group a Sponsor for the organization, in which case the group members can approve requests for all business services in the organization.
Click the
tab to add a role at the organization level, click the tab to add a role at the business group level, or click the tab to add a role at the business service level.Click the role that you want to assign
For example, if you selected the
tab and you want to enable the user group to create business services for the business group, click .Click
, select the object (organization, business group, or business service) to which you want the role to apply, then click to add it to the list.When you have finished assigning roles to the user group, click
.For more information about user groups and roles, see Section 11.0, Setting Up and Managing Users.