User Management
  • 08 Jun 2021
  • 2 دقائق للقراءة
  • المساهمون
  • داكن
    ضوء
  • PDF

User Management

  • داكن
    ضوء
  • PDF

The content is currently unavailable in Arabic. You are viewing the default English version.
ملخص المقال

Serverless360 lets organisations manage their Azure resources, those constitute their Line of Business. As an organisation you can add any number of their employees as users to your Serverless360 account, to manage the associated resources. Employees using Serverless360 should be provided with exact permission they need. Too many permissions can expose an account to security violations. Insufficient permissions mean that your employees can’t get their work done efficiently. User access policy with custom role capability helps address this problem of offering fine-grained access management for Serverless360.

User Roles

Serverless360 Private Hosting authenticates your organization users using your Azure Active Directory (AD). Users can be managed through the User Management feature under Settings module in Serverless360. New user can be assigned a role to define access control. The following table provides brief descriptions of the built-in roles:

RoleDescriptionCANCAN'T
AdministratorAs an account owner, you have full control over the application including access to licensingCreates and manages all resources, Invite Users to the account, Switch Account ownership to other Super User, Perform License Activation and Deactivation-
Super UserWill have access to the whole application except licensingCreates and manages all resources, Invite Users to the accountManage license
Normal UserWill not have access to SettingsCreate and manage all associated entitiesCan’t access Setting module that includes: Service Principal management, User Management, License Management, Event Logs

Use Case

Consider a business scenario, where the requirement is to provide Read-Only permission on a set of composite applications to a specific set of users. In this scenario, you can create a custom role definition along with the predefined roles.

  1. Click 'Add Role' in the User Management screen
  2. Enter a 'Role Name' and 'Role Description'
  3. Select the Composite Applications that should be accessible to this role
  4. Define Overall permission, applicable on the selected Composite Applications and its associated entities:
    1. Read Only- can view
    2. Manage - can manage
  5. Define permissions on 'Operations'
    1. Retrieve Message - Can view the message list and system properties
    2. Access Message Content - Can access message details like Custom Properties and Message body
    3. Process Message - Can perform message operations like defer, resubmit, repair & resubmit and delete the message
  6. Define permissions on 'Monitoring'
    1. 'View Alert History' -Can view the alert histories of the monitors already created
    2. 'Manage' - Can manage monitors

PH-User-role1.png

Define the permission on Technology Stack, explicitly for Service Bus, Logic Apps, and Azure Functions to permit CRUD operations on the associated entities. Choosing

  1. Read Only - can view associated entities
  2. Manage - can perform CRUD operation on the associated entities
  3. Select View or Download option on Governance & Audit

PH-User-role2.png

Additional Pointers

Serverless360 custom role can be leveraged to:

  • Restrict users to hold:

    • read-only or manage access to a selected Composite Applications (Logical group of Azure resources)
    • read-only or manage access to a specified Technology stack (Service Bus, Logic App, Azure Function etc)
    • permission only to Process Messages on entities associated within a Composite Application
    • permission only to perform a specified action like View and Download Governance and Audit report
    • as the business scenario demands
  • Define custom permissions to a group of users


هل كانت هذه المقالة مفيدة؟

Changing your password will log you out immediately. Use the new password to log back in.
First name must have atleast 2 characters. Numbers and special characters are not allowed.
Last name must have atleast 1 characters. Numbers and special characters are not allowed.
Enter a valid email
Enter a valid password
Your profile has been successfully updated.