Administer > Configure Security > Control Menu Access

Control Menu Access

Access to the Tools and Actions menu items is controlled by Security Group Mapping configuration settings: User Group, Security Group, and Object Access Privilege

See Determine which NNMi User Group to Assign for additional information about User Group limitations. See Object Access Privileges Provided in NNMi and Actions provided by NNMi for additional information about Object Access Privileges.

You can also right-click any object in a table or map view to access the items available within the Actions menu.

Note the following:

  • User Groups determine access to NNMi console workspaces, views and forms. User Groups also determine the Tools and Actions that the users in the User Group can access.
  • You MUST assign each User Account to one of the predefined NNMi User GroupNNMi User Groups are those User Groups provided by NNMi. Users cannot access the NNMi console until their User Account is mapped to at least one of the following NNMi User Groups: NNMi Administrators, NNMi Level 2 Operators, NNMi Level 1 Operators (with more limited access privileges than Level 2 Operators), and NNMi Guest Userss before that user can access NNMi. See User Groups Provided in NNMi for more information.
  • If you map a User Account to two or more NNMi User Groups, NNMi gives the User Account the privileges associated with each User Group to which the User Account is assigned.
  • Security Groups are optional and control (through User Groups) which Users can access a node and its hosted objects, such as an interface. Each node is associated with only one Security Group.

    Note Users see only those members of an object group (for example, Node Group or Router Redundancy Group) for which they have access. If a user cannot access any nodes in the group, the group is not visible to that user. 

  • Object Access Privileges are associated only with Security Groups and their associated User Groups. Object Access Privileges determine the Tools and Actions that the User Group can access for the nodes they are permitted to view.

    • If a User Account is assigned an NNMi User Group with more privileges than the Object Access Privilege, the user sees all of the actions available for the User Group (not restricted because of the Object Access Privilege setting). For example, if a User Account is assigned to the User Group NNMi Level 2 Operators and has an Object Access Privilege of Object Operator Level 1 (with more limited access privileges than Level 2 Operators) for a set of nodes, the operator sees all actions available to Level 2 Operators.
    • If a User Account is assigned an NNMi User Group with less privileges than the Object Access Privilege, the user will not see all of the actions available for the Object Access Privilege. For example, if a User Account is assigned to the User Group NNMi Level 1 Operators (with more limited access privileges than Level 2 Operators) and has an Object Access Privilege of Object Operator Level 2 for a set of nodes, the operator will see only those actions available to Level 1 Operators. As an NNMi administrator, you must do either of the following:

      • Configure the Menu Item Context Basic Details to change the Required NNMi Role for the menu item
      • Assign the operator User Account to the NNMi Level 2 Operators User Group.
  • All menu items are visible to users with a role that can use the items, but an Access Denied message displays when any user with insufficient Object Access privileges tries to use a menu item. For example, both Level 1 or Level 2 Operators are denied access to the Communication Settings action.
  • You can restrict access to certain Launch Actions (provide tighter security than those enforced by the default settings). See Configure Menu Item Context Basic Details for more information about configuring actions.
  • If the menu item does not require node access, (for example, Status Details for a Node Group) NNMi uses the privileges assigned to the NNMi User Group that is mapped to the User Account.

User Group and Object Access Privilege Required for the Tools Menu:

User Group and Object Access Privilege Required for the Actions Menu:

See Investigate and Diagnose Network Problems for more information about these actions.

Note Each Tools and Action menu item provided by NNMi is also associated with a default NNMi Role. (To determine the default NNMi Role assigned to each Action menu item, see Actions provided by NNMi.) If you change the setting for a Menu Item provided by NNMi to a Role that is a lower level Role than the default NNMi Role assigned to the menu item, NNMi ignores that change. Any User Group with the lower level Role than the default NNMi Role cannot access the menu item.