6.1.2 Configuring Resource Pools

Resource Pools contain resources of similar type. The following sections explain how you can manage resource pools.

The following sections explain how to manage resource pools:

Adding a Resource Pool

  1. On the home page of the console, click Access Control.

  2. In the navigation pane, click Resource Pools.

  3. In the details pane, click Create. A left pane with Create Resource pool is displayed with General and Resources settings.

  4. In the Resources page, specify a name for the Resource Pool.

  5. Add a Description.

  6. Specify the Type of resource pool from the list.

  7. Click Next. Resources page is displayed for configuration.

  8. Click Add. Select the resources.

  9. Click Add.

  10. Select or enter the Default Credential. For more information, see Default Credential.

  11. Click Create.

Modifying a Resource Pool

  1. On the home page of the console, click Access Control.

  2. In the navigation pane, click Resource Pools.

  3. In the details pane, select the resource pool you want to modify, then click the edit icon next to the resource pool name or click on the resource pool you want to modify and Edit Resource Pool page opens up on the right pane.

  4. Configure the following fields:

    Name: Specify a name for the resource pool.

    Description: Describe the purpose of this resource pool.

    NOTE:You cannot modify the type of the resource pool.

  5. Click Next. Resources page is displayed for configuration.

  6. Add or Remove resources.

  7. (Optional) Modify the default credential.

  8. Click Save.

Deleting a Resource Pool

  1. On the home page of the console, click Access Control.

  2. In the navigation pane, click Resource Pools.

  3. In the details pane, select the resource pool you want to delete, then click the delete icon next to the resource pool name.

    To select multiple resource pools, select multiple resource pools from the list.

  4. Click Delete.

NOTE:Resource Pool cannot be deleted, if it a part of an assignment.

Default Credential

A credential with least privileges, should be selected as a Default Credential, for each resource added in a Resource Pool. This would help organizations in implementing the least privilege model as per the security recommendations and also minimizes the effort required to select a Credential while creating the access permissions.

Windows Agents

To create permissions in Access Control, each Windows Agent must be linked with a Credential Vault, where the Credentials are stored for single sign-on purposes for respective Agents. To link a Windows Agent with a Credential Vault follow the procedure:

  1. Go to Hosts select Windows Agent.

  2. Click Modify Host and select a value for the Vault.

  3. Click Finish.

    You can link the following two types of Windows Agents:

    • Active Directory type Credential Vaults can be used for linking, if the Windows Agent is connected to an Active Directory Domain and to reference only Active Directory accounts in the Agent.

    • Windows Hosts type Credential Vaults can be used for linking, if the Windows Agent is a stand-alone Windows Host or a Windows Agent which is part of a Domain but also has Local Accounts. To reference both the Local Accounts and Active Directory accounts in the Agent, the Windows Host type vault in Credential Vault should be linked to an Active Directory domain.

Linux/Unix Agents

  • These Resources can use a username as Default Credential, which should be typed-in. For example, root or administrators.

SSH or Telnet Servers

  • These Resources can use any Credential, which belongs to them in the Credential Vault.

Windows Servers

  • These Resources can use any Credential, which belongs to them in the Credential Vault or the linked Active Directory domain.