Asset Management Suite

 View Only
  • 1.  Asset Management Permissions

    Posted Mar 23, 2011 09:51 AM

    Hi!

    Again I'm fighting with permissions on Altiris. This time I want to give a Security Role permissions to do the following:

    1. CMDB Functions - Set Asset Status
    2. CMDB Functions - Set Asign Owner
    3. Edit Computer Ressources

    I tried to give permissions to computer ressources which didn't help. Wher do I have to give permissions to enable a SR to do above tasks?

     

    THX 



  • 2.  RE: Asset Management Permissions

    Posted Mar 31, 2011 02:21 AM

    for CMDB Functions -> Set Asset Status,

    1. Go to Security Role Manager of the Role
    2. Go to Settings -> Notification Server -> Right Click Menu -> CMDB Functions -> Set Asset Status. (Choose Asset Status for which user has to permission or assign Read/Write Controls on the Parent folder Set Asset Status).
    3. Save Changes.

    Note: These changes may not replicate to Edit page. For ex: If you set the user to access only certain statuses (Ex: Active/Instock) via right click actions, user would still be able to assign other restricted status's from edit page if he has permissions on Asset Status Resource Association.so, Make sure user has no access to this Resource Association but just the Right Click Menu.

    for CMDB Functions -> Set Assign Owner

     same as above, but parent folder now is Assignment Functions

    for Editing Computer Resource

     I need more information here - like

    1. If the user is able to view the computer resource instance but not be able to edit it .
    2. If the user can't Just see 'Create computer' when right click on Computer Resource Type in the tree
    3. If the user can't view the computer resource Type at all in the Tree (Home -> Service and Asset Management -> Manage Configuration Items).

     

    Hope this helps,

    Prasanna.

     

     

     

     

     



  • 3.  RE: Asset Management Permissions

    Posted Apr 11, 2011 03:19 AM

    Thx!

    For editing: User should see the computer ressources just out of a report and choose "edit" by right clicking the computer.

    RG, T



  • 4.  RE: Asset Management Permissions

    Posted Apr 12, 2011 10:00 PM

    Resource Instances are now controlled by Organizational Groups and Views

    Make sure user has Read & Write permissions on default Organizational Group or the Org group that has user access to.

    This should enable users to edit resource instances.

    -Prasanna



  • 5.  RE: Asset Management Permissions

    Posted Apr 13, 2011 08:29 AM

    Added permissions to Org. View and to the ressource computers (NS\Resource Data Class settings\Res Types\Asset types\IT\Computers) and set the right click permissions to see the "Edit" button.

    Permissions I set on "Computers":

     

    System Permissions Check All   Clear All
     

    After pressing the "Edit" butten I get:

     

    Resource Edit Denied
      You do not have permission to edit resources of type Computer.

    Where do i still need to set permissions?



  • 6.  RE: Asset Management Permissions
    Best Answer

    Posted Apr 14, 2011 12:22 AM

    Interesting.. That should allow you to edit.

    we'll just do a revision of steps again just to make sure:

    1. Go to Security Role Manager of the Role.

    2. Verify if the user has 'read' on resource Type - select Settings from View dropdown label, Select settings -> Notification Server -> Resource and DataClass Settings -> Resource Types -> Asset Types -> IT -> Computer. Check that user has 'Read' and 'Create Resource Instance' permissions on this resource type.

    3. Select if the user 'Edit' permission in the right click menu - Settings -> Notification Server -> Right Click Menu -> Edit (there are two edit's here). Ensure user has 'read' permission on both of them.

    4. As you can see computer and also edit item action, first two steps should be ok with you as well. May be you're something in here ---- Select Resources from the View dropdown Label. Select Organizational Views ->Default -> Ensure user has read, write, create children permission on this group.

         4.1 -- Once this is done, you can also click on Asset -> Network resource -> Computer and check if the permissions given above are inherited from the parent ( Computer should have Read, write, Create Children permissions). if not, you've to inherit these permissions from parent by clicking on 'advanced' button at the bottom, untick 'Inherit permisisons entries from the parent object that apply to child objects) and save changes. choose copy from prompt that shows up. Now you can add permissions manually (read, write, create children).

    And this should defintely allow you to get edit control on the resource instance.

    In case, you don't want to choose default org group and give only control to the instances they've created- make sure the computer instances are in the Org group they have access to.

    Hope this helps.

    -Prasanna.



  • 7.  RE: Asset Management Permissions

    Posted Apr 14, 2011 04:25 AM

    Working now! THANK YOU!