User Authorizations
Authorizations allow users to perform specific tasks, such as creating shares,
rebooting the appliance, and updating the system software. Authorizations are grouped
into scopes, and each scope may have a set of optional filters to
narrow the scope of the authorization. For example, rather than an authorization to
restart all services, a filter can be used so that this authorization can restart the
HTTP service only.
The following table shows the available scopes:
Table 39 User Available Scopes, Filters, and Authorizations
|
|
|
|
Active Directory
|
ad
|
Domain or workgroup name
|
|
Alerts
|
alert
|
-
|
Configure alert filters and thresholds
|
Analytics
|
stat
|
List of drilldowns
|
-
Configure analytics hostname lookup policy
-
Create a statistic with this drilldown present
-
Read a statistic with this drilldown present
|
Appliance
|
appliance
|
Appliance name
|
-
Emit an audit log entry
-
Restore the appliance to factory defaults
-
Power down the appliance
-
Reboot the appliance
-
Modify the appliance name
-
Access the underlying Solaris shell
-
Configure system certificates
-
Configure trusted certificates
|
Clustering
|
cluster
|
-
|
-
Failback resources to a cluster peer
-
Reset a failed cluster I/O device
-
Takeover resources from a cluster peer
-
Transfer resources to a cluster peer
|
Datasets
|
dataset
|
-
|
Configure dataset retention policies
|
Hardware
|
hardware
|
-
|
-
Online and offline disks
-
Configure LEDs on disks, appliance, and external
enclosures
-
Configure network properties for the service
processor
-
Remove a drive as a hot spare
-
Configure a storage pool
-
Unconfigure a storage pool
|
Keystores
|
keystore
|
Keystore name
|
-
List keys present in a per-user keystore
-
Permit keystore modifications
-
Permit read access to sensitive values in a
keystore
|
Networking
|
net
|
-
|
Configure networking devices, datalinks, and interfaces
|
Projects and shares
|
nas
|
-
Storage pool
-
Project
-
Share
|
-
Configure who can access a share
-
Change general properties on a share
-
Configure protocol-specific properties
-
Change quota and reservation on a share
-
Change user and group quotas on a share
-
Clear locks held on behalf of an NFS client
-
Clone a snapshot to a normal filesystem
-
Create a project
-
Create a filesystem or LUN
-
Remove a project or share
-
Manage encryption keys for a project or share
-
Promote a clone
-
Rename a project or share
-
Rollback a filesystem to a previous snapshot
-
Configure data replication to other appliances
-
Manage data replicated from other appliances
-
Configure a recurring schedule of snapshots
-
Check a storage pool for errors
-
Manage shadow migration on a share
-
Take a manual snapshot
|
Roles
|
role
|
Role name
|
|
SAN
|
stmf
|
-
|
Configure SAN hosts and targets
|
Services
|
svc
|
Service name
|
|
Shares property schema
|
schema
|
-
|
Modify property schema
|
Update
|
update
|
-
|
-
Delete system software
-
Update system software
-
Upload system updates
|
Users
|
user
|
Username
|
-
Configure authorizations for a user
-
Change a password
-
Configure preferences for a user
-
Configure properties for a user
-
Configure roles for a user
-
Create a user
-
Destroy a user
|
Workflow
|
workflow
|
|
-
Delete workflow
-
Execute workflow
|
Worksheet
|
worksheet
|
|
-
Modify worksheet
-
Read worksheet
|
|
Related Topics
-
Adding an Administrator or User BUI, CLI
-
Changing a User Password BUI, CLI
-
Editing Exceptions for a User BUI, CLI
-
Deleting Exceptions for a User BUI, CLI
-
Adding a Role BUI, CLI
-
Editing Authorizations for a Role BUI, CLI
-
Deleting Authorizations from a Role BUI, CLI
-
Adding a User Who can Only View the Dashboard BUI