Default settings

By default, ROOT role is disabled to avoid modifications. From the Role Assignment tab, admin user can be assigned to multiple roles in addition to ROOT role but ROOT role cannot be removed from the admin user.

  • If an application is imported using XML Importer utility, by default ROOT role will not have access to the imported applications. Admin user must navigate to ROOT role to sync the permissions.

    Create a role using the userID of the user who is intended to perform the role of an LDAP Admin. Refer to the Setting up an LDAP Admin topic for more details. Assign all permissions and add the required users/user groups to this role. The LDAP Admin can then create the following roles:

  • Regular User: Refers to a role created for users who are responsible for running rules and reviewing results. The users should be granted permissions to log into the A&AS Web Explorer to perform these operations. The LDAP Admin should specify the applications that a Regular User role can access and grant View and Run Task permissions. LDAP userIDs and/or LDAP user groups should be assigned to the role.
  • Power User: Refers to a role created for users who are granted permissions to create and edit rules along with the permissions granted to a Regular User role. The LDAP Admin should assign the Manage Tasks and Folders permission. The Power User should be able to login to Windows A&AS Rule Editor and Explorer to create or edit rules. The Power user should be able to access the A&AS Web Explorer.
  • Administrator: Refers to the role created for a user who is granted permissions to create roles, assign permissions, and assign users or user groups to the role. The Administrator typically creates and manages applications. Therefore, the General and Application permissions should be granted to the role. The LDAP administrator should be able to access the A&AS web application, A&AS Web Explorer, and Windows A&AS Rule Editor and Explorer using LDAP authentication.