Dell Unity Access Control and User Profile Capabilities.
Summary: This KB details the Management account roles on the Dell Unity and Dell Unity XT systems.
Instructions
Management roles:
● Adminstrator
● Storage Administrator
● Security Administrator
● Operator
● VM Administrator
After the storage system initial system configuration process is complete, you can manage the storage system users and groups (either local accounts, LDAP accounts, or both) from Unisphere or the Unisphere CLI.
For local accounts, you can add a new user, delete a selected user, change the user's role, and reset (change) user password.
For an LDAP user, you can add an LDAP user, delete a selected user, and change the user's role.
For an LDAP group, you can add an LDAP group, delete a selected group, and change the group's role.
The Admin user is used to log into the Unisphere GUI and has the Administrator role.
The Service user is used to log into the Unity CLI.
You cannot create or delete storage system service accounts.
You can reset the service account password from Unisphere.
To change the Service user password under System, select Service > Service Tasks > Change Service Password.
Note: A table style display of the following information is available on the referenced source document if required.
Administrator users can:
Change own local login password.
Add, delete, or modify hosts.
Create storage, Delete storage, Add storage objects, such as LUNs, shares, and storage groups to a storage resource.
View storage configuration and status.
View Unisphere user accounts.
Add, delete, modify, lock or unlock Unisphere user accounts.
View current software or license status.
Perform software or license upgrade.
Perform initial configuration.
Modify NAS server configuration.
Modify system settings.
Modify network settings.
Change management interface language.
View log and alert information.
View encryption status.
Perform encryption keystore, auditlog, checksum backup.
Modify security settings (FIPS 140-2 mode, TLS mode, and restricted shell mode).
Establish VASA connections between vCenter and the storage system.
Storage Administrator users can:
Change own local login password.
Create storage.
Delete storage.
Add storage objects, such as LUNs, shares, and storage groups to a storage resource.
View storage configuration and status.
View current software or license status.
Change management interface language.
View log and alert information.
View encryption status.
Security Administrator users can:
Change own local login password.
View storage configuration and status.
View Unisphere user accounts.
Add, delete, modify, lock or unlock Unisphere user accounts.
View current software or license status.
Change management interface language.
View log and alert information.
View encryption status.
Modify security settings (FIPS 140-2 mode, TLS mode, and restricted shell mode).
Operator users can:
Change own local login password.
View storage configuration and status.
View current software or license status.
Change management interface language.
View log and alert information.
View encryption status.
VM Administrator users can:
Establish VASA connections between vCenter and the storage system.
You can change account roles in Unisphere by selecting Settings and, under Users and Groups, select User Management > More Actions > Change Role.