Users, Roles, and Permissions
The Cisco ACI Multi-Site Orchestrator allows access according to a user’s role defined by role-based access control (RBAC). Roles are used in both local and external authentication. The following user roles are available in Cisco ACI Multi-Site Orchestrator.
-
Power User—A role that allows the user to perform all the operations.
-
Site Manager—A role that allows the user to manage sites, tenants, and associations between them.
-
Schema Manager—A role that allows the user to manage all schemas regardless of their tenant associations.
-
Schema Editor—A role that allows the user to manage schemas that contain at least one tenant to which the user is explicitly associated.
-
User Manager—A role that allows the user to manage all the users, their roles, and passwords.
Each role above is associated with a set of permissions, which in turn are used to show relevant and hide irrelevant elements from the user's view of the Orchestrator GUI. For example, the User Manager role has only the user-related permissions associated with it and as such the user with that role will only see Users and Admin tabs in the GUI.
User Roles and Permissions
The following table lists the Cisco ACI Multi-Site permissions allowed with each available user role. The Attribute-Value (AV)
column specifies the user configuration string required when configuring an external authentication server for use with the
Multi-Site Orchestrator. External authentication is covered in more detail in the Administrative Operations chapter.
User Role |
Permissions |
Attribute-Value (AV) Pair |
---|---|---|
Power User |
|
|
Site Manager |
|
|
Schema Manager |
|
|
Schema Editor |
|
|
User Manager |
|
|
Admin User
In the initial configuration script, a default admin
user account is configured and is the only user account available when the system starts. The initial password for the admin user is set by the system and you are prompted to change it after the first log in.
-
The
admin
user's default password isWe1come2msc!
-
The
admin
user is assigned the Power User role. -
Use the
admin
user to creating other users and perform all other Day-0 configurations. -
The account status of the admin user cannot be set to Inactive.
Read-Only Access
Each of the user roles above can be assigned in read-only mode. When read-only permissions are granted, the user can view any fabric objects available to that role just like before, but they cannot make any changes to those objects.