McAfee EPOCDE-AA-BA Product Guide - Page 48

By permission set Shared Groups, Queries and Reports

Page 48 highlights

6 Setting up permission sets How users, groups, and permission sets fit together An example access configuration As an example, let's say you want to give all users from your "Dallas" Active Directory server access to a specific group of reports, and you want one particular engineer (let's call her "ElaineG") to be able to create and modify queries in that group. To accomplish this, you'll need to create two permission sets and one group, and edit ElaineG's user account. 1 Create a permission set called "Dallas Users." 2 Add the Dallas Active Directory server to the list called Active Directory groups mapped to this permission set. 3 Make sure they have the Queries and Reports permission Use all public groups and the shared groups below; create and edit personal queries/reports. as well as other permissions you want to grant. 4 Duplicate the "Dallas Users" permission set and call the new set "Dallas Report Creators". 5 Create a query group called "Dallas Reports" and give it By permission set (Shared Groups) visibility to the "Dallas Users" and "Dallas Report Creators" permission sets. 6 In the "Dallas Users" permission set, select the "Dallas Reports" group under Queries and Reports permissions. Do the same for the "Dallas Report Creators" permission set. 7 Change the Queries and Reports permission in this new permission set to Edit public groups and the shared groups below; create and edit personal queries/reports; make personal queries/reports public. The list of selected groups should not change. 8 Edit ElaineG's user account and assign her to the "Dallas Report Creators" group. You've now got an entire class of users (members of the "Dallas" Active Directory server) with access to a specific query group, and an individual with the ability to create and modify queries and reports within that group. 48 McAfee® ePolicy Orchestrator® 4.6.0 Software Product Guide

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322
  • 323
  • 324
  • 325
  • 326
  • 327
  • 328

An example access configuration
As an example, let's say you want to give all users from your "Dallas" Active Directory
server access to a specific group of reports, and you want one particular engineer (let's call
her "ElaineG") to be able to create and modify queries in that group. To accomplish this,
you'll need to create two permission sets and one group, and edit ElaineG's user account.
1
Create a permission set called "Dallas Users."
2
Add the Dallas Active Directory server to the list called
Active Directory groups mapped to this
permission set
.
3
Make sure they have the
Queries and Reports
permission
Use all public groups and the shared groups
below; create and edit personal queries/reports.
as well as other permissions you want to grant.
4
Duplicate the "Dallas Users" permission set and call the new set "Dallas Report Creators".
5
Create a query group called "Dallas Reports" and give it
By permission set (Shared Groups)
visibility to the "Dallas Users" and "Dallas Report Creators" permission sets.
6
In the "Dallas Users" permission set, select the "Dallas Reports" group under
Queries and
Reports
permissions. Do the same for the "Dallas Report Creators" permission set.
7
Change the
Queries and Reports
permission in this new permission set to
Edit public groups and
the shared groups below; create and edit personal queries/reports; make personal queries/reports public
. The
list of selected groups should not change.
8
Edit ElaineG's user account and assign her to the "Dallas Report Creators" group.
You've now got an entire class of users (members of the "Dallas" Active Directory server)
with access to a specific query group, and an individual with the ability to create and
modify queries and reports within that group.
6
Setting up permission sets
How users, groups, and permission sets fit together
48
McAfee
®
ePolicy Orchestrator
®
4.6.0 Software Product Guide