Table 7-9. Default Role Group Privileges

Role

Default Privilege

Permissions Granted

Bit Mask

Groups

Level

 

 

 

 

 

 

Role

Administrator

Login to iDRAC, Configure

0x000001ff

Group 1

 

iDRAC, Configure Users, Clear

 

 

 

Logs, Execute Server Control

 

 

 

Commands, Access Virtual

 

 

 

Console, Access Virtual Media,

 

 

 

Test Alerts, Execute Diagnostic

 

 

 

Commands

 

 

 

 

 

Role

Operator

Login to iDRAC, Configure

0x000000f9

Group 2

 

iDRAC, Execute Server Control

 

 

 

Commands, Access Virtual

 

 

 

Console, Access Virtual Media,

 

 

 

Test Alerts, Execute Diagnostic

 

 

 

Commands

 

 

 

 

 

Role

Read Only

Login to iDRAC

0x00000001

Group 3

 

 

 

 

 

 

 

Role

None

No assigned permissions

0x00000000

Group 4

 

 

 

 

 

 

 

Role

None

No assigned permissions

0x00000000

Group 5

 

 

 

 

 

 

 

NOTE: The Bit Mask values are used only when setting Standard Schema using RACADM.

Single Domain Versus Multiple Domain Scenarios

If all the login users and role groups, and the nested groups, are in the same domain, then only the domain controllers’ addresses must be configured on iDRAC6. In this single domain scenario, any group type is supported.

If all the login users and role groups, or any of the nested groups, are from multiple domains, then Global Catalog server addresses are required to be configured on iDRAC6. In this multiple domain scenario, all the role groups and the nested groups, if any, must be a Universal Group type.

Using the iDRAC6 Directory Service

169

Page 169
Image 169
Dell IDRAC6 manual Single Domain Versus Multiple Domain Scenarios, 169, Default Role Group Privileges