To grant a user administrative access to a Control Center or to a CC managed box, an individual administrator account must be created for every dedicated person. However, if such a user is also part of a group that is handled by external authentication services, the respective accounts must be multi-managed. To avoid this drawback, it is possible to grant administrative access to a Control Center based on user groups from external authentication systems, without the need to explicitly configure an administrator account on the Control Center or on the CC managed box.
Users that gain administrative access via mapping from external authentication services cannot log into the Control Center via SSH. In addition, there is also no allow list or block list in the group filtering.
Before You Begin
Log into your CC on box level to enable external authentication services. For more information, see Authentication.
Step 1. Create a Template to Map the Login Information from External Authentication Services to Your Control Center
For mapping the login information, first create a CC Admin user for an external authentication. For this, execute the following steps in the article How to Configure Administrative Profiles.
- Step 1. Add a Control Center Administrator
- Step 2a. Configure External Authentication Settings
Step 2. Map the Account of the External Administrator
- Go to CONFIGURATION > Multi-Range > Global Settings > Administrative Roles.
- In the left navigation bar, click External Admins.
- Click Lock.
- From the Enable External Admins list, select Yes.
- From Authentication Scheme, select the authentication scheme where the external admin is registered in.
- Deselect the Other check box.
- Click + to enter an entry to the Definitions table. The Definitions window opens.
- Enter the Name for the definition.
- From the Admin template name list, select the entry that refers to your mapping information in Step 1. E.g., MapAdmins.
- Deselect the Other check box.
- In the Ext. Groups section, click +.
- Enter the name of the group the user is a member of in the external authentication service.
- Click OK.
- Click Send Changes and Activate.
You can now log into your Control Center as an administrator with the credentials of your external authentication service.