NetBackup™ Web UI Administrator's Guide
- Introducing the NetBackup web user interface
- Section I. Managing security
- Monitoring and notifications
- Managing role-based access control
- Configuring RBAC
- Role permissions
- Global > NetBackup management
- Global > Security
- Global > Storage
- Global > NetBackup management
- Manage access
- Configure an external certificate for the NetBackup web server
- Security events and audit logs
- Managing security certificates
- Managing user sessions
- Managing master server security settings
- About trusted master servers
- Creating and using API keys
- Configuring authentication options
- Managing hosts
- Troubleshooting the web UI
- Section II. Managing storage and backups
- Configuring storage
- Managing protection plans
- Managing protection plans for Microsoft SQL Server
- Usage reporting and capacity licensing
- Configuring storage
- Section III. Veritas Resiliency Platform
- Section IV. Managing credentials
Sign-in options for the NetBackup web UI
NetBackup supports authentication of local domain users and Active Directory (AD) or LDAP domain users. AD and LDAP domains, smart card, and Single Sign-On (SSO with SAML) requires separate configuration for each master server domain where you want to use the authentication method.
NetBackup supports the following types of user authentication:
User name and password
Digital certificate or smart card, including CAC and PIV
This authentication method only supports one AD or LDAP domain for each master server domain and is not available for local domain users.
See Configure user authentication with smart cards or digital certificates.
Single sign-on, with SAML
Note the following requirements and limitations.
To use SSO, you must have a SAML 2.0 compliant identity provider configured in your environment.
Only one AD or LDAP domain is supported for each master server domain. This feature is not available for local domain users.
Configuration of the IDP requires the NetBackup APIs or the NetBackup command nbidpcmd.
API keys are used to authenticate a user or a group and cannot be used with SAML-authenticated users or groups.
Global logout is not supported.