Configuring User Roles
A role refers to a logical entity used for determining user access to devices and application services in Aruba Central. Users are always tagged to roles that govern the level of user access to the Aruba Central applications and services.
Access control for federated users is determined by the attributes set in the IdP.
Aruba Central supports a set of predefined roles with different privileges and access permissions. You can also configure custom roles.
Predefined User Roles
The
page allows you to configure the following types of users with system-defined roles:
Application |
User Role |
Privilege |
---|---|---|
|
|
Administrator for the page. If there are common modules between and other app(s), the user role has higher precedence and the user is granted permission if the operation is initiated from the page. |
|
Can view and modify settings in the page and all pages. |
|
|
Can view the page and all pages. |
|
|
|
Administrator for the application. Has access to > . This is applicable only if the role is not set or is not conflicting. |
|
Cannot view the application. |
|
|
Has guest operator access for the application. User does not have access to > . |
|
|
Has read-only access to > and the application. |
|
|
Has read-write access to > and the application.Has access to view and modify data using the Aruba Central UI or APIsApplication Programming Interface. Refers to a set of functions, procedures, protocols, and tools that enable users to build application software.. However, the user cannot execute APIs to: Perform operations in the following pages:
|
Custom Roles
Along with the predefined user roles, Aruba Central also allows you to create custom roles with specific security requirements and access control. However, only users with the administrator role and privileges can create, modify, clone, or delete a custom role in Aruba Central.
With custom roles, you can configure access control at the application level and specify access rights to view or modify specific application services or modules. For example, you can create a custom role that allows access to a specific applications like Group Management or Network Management and assign it to a user.
MSP tenant account users cannot add, edit, or delete roles.
Adding a Custom Role
The following are the permissions that you can associate with a custom role:
- User roles with permission can perform add, edit, or delete actions within the specific module.
- User roles with permission can only view the specific module.
- User roles with permission cannot view that particular module.
To add a custom role, complete the following steps:
-
In the
page, under , click . -
Click the
tab. -
Click
. The window is displayed. -
Specify a name for the role.
-
From the drop-down list, select one of the following:
- Aruba Central. —To set permissions at the module level in the application. —To manage access to devices and subscriptions in
-
For Network Management, you can set access rights at the module level. To set view or edit permissions or block the users from accessing a specific module, complete the following steps:
- Click .
-
Select one of the following options for each module as required:
- Click .
- Assign the role to a user account as required.
Module Permissions
Aruba Central allows you to define user roles with or permissions. You can also block user access to some modules. For example, if the Guest Access module is blocked for a specific user role, the corresponding pages are not displayed in the UI.
Aruba Central supports setting permissions for the following modules:
Application |
Module |
Description |
---|---|---|
|
|
Allows users to add devices and assign keys and subscriptions to devices. |
|
|
Allows users to create, view, modify, and delete groups and assign devices to groups. |
|
Allows users to add devices and assign subscriptions to devices. |
|
|
Allows users to configure, troubleshoot, and monitor Aruba Central-managed networks. |
|
|
Allows user to access VisualRF and RFRadio Frequency. RF refers to the electromagnetic wave frequencies within a range of 3 kHz to 300 GHz, including the frequencies used for communications or Radar signals. heatmaps. |
|
|
Allows users to access the Unified Communications pages. |
|
|
Allows users to view and create reports. |
|
|
Allows users to access other applications modules such as notifications and Virtual Gateway deployment service. |
Viewing User Role Details
To view the details of a user role, complete the following steps:
- In the page, under , click .
-
Click the
tab. The tab displays the following information:- —Name of the user role.
- —The applications to which the users have access.
- —Number of users assigned to a role.
Editing a User Role
To edit a user role, complete the following steps:
- In the page, under , click .
- Click the tab.
- In the table, select the role and click the edit icon.
- In the window, modify the permissions set for module(s).
- Click .
Deleting a User Role
To delete a user role, ensure that the role is not associated to any user and complete the following steps:
- In the page, under , click .
- Click the tab.
- In the table, select the role and click the delete icon.
- Confirm role deletion in the dialog box.