NetBackup™ Web UI Administrator's Guide
- Introducing the NetBackup web user interface
- Section I. Managing security
- Monitoring and notifications
- Managing role-based access control
- Configuring RBAC
- Role permissions
- Global > NetBackup management
- Global > Security
- Global > Storage
- Global > NetBackup management
- Manage access
- Configure an external certificate for the NetBackup web server
- Security events and audit logs
- Managing security certificates
- Managing user sessions
- Managing master server security settings
- About trusted master servers
- Creating and using API keys
- Configuring authentication options
- Managing hosts
- Troubleshooting the web UI
- Section II. Managing storage and backups
- Configuring storage
- Managing protection plans
- Managing protection plans for Microsoft SQL Server
- Usage reporting and capacity licensing
- Configuring storage
- Section III. Veritas Resiliency Platform
- Section IV. Managing credentials
Role permissions
Role permissions define the operations that roles users have permission to perform.
Table: Role permissions for NetBackup RBAC
Category | Description | ||
---|---|---|---|
Global permissions apply to all assets or objects. For example, in NetBackup 8.3, or permissions cannot be applied to specific jobs or hosts. A role with or permissions apply to all jobs or hosts. | |||
Configuration and management of NetBackup. | |||
NetBackup backup policies and storage lifecyle policies. See Global > Protection. | |||
NetBackup security settings. See Global > Security. | |||
Manage backup storage settings. See Global > Storage. | |||
Manage assets Cloud, Microsoft SQL Server, RHV, Universal shares, and VMware. See Assets. Note: Assets can only be added when you create a role and cannot be added to an existing role. | |||
Manage how backups are performed with protection plans. See Protection plans. Note: Protection plans can only be added when you create a role and cannot be added an existing role. | |||
Manage credentials for Microsoft SQL Server and external KMS. See Credentials. Note: Credentials can only be added when you create a role and cannot be added to an existing role. |
Note the following when you configure the permissions for RBAC roles:
RBAC only controls access to the web UI and not the NetBackup Administration Console.
When you create roles, be sure to enable the minimal number of permissions so the user can sign in to and use the web UI. Some individual permissions do not have a direct correlation with a screen in the web UI. Users that attempt to sign in but that only have a permission of this kind receive an "Unauthorized" message.
If a user is added to or removed from a role, the user must sign out and sign in again before the user's permissions are updated.
Most permissions are not implicit.
In most cases a
permission does not give a user permission. A permission does not give a user permission or other recovery options like .Not all RBAC-controlled operations can be used from the NetBackup web UI. (For example, NetBackup backup images can only be viewed and managed from the APIs or the NetBackup Administration Console.) These types of operations are included in RBAC so a role administrator can create roles for API users as well as web UI users.
Some tasks require a user to have permissions in multiple RBAC categories. For example, to establish a trust relationship with a remote master server, a user must have permissions for both
and .