Summary
The Software Vulnerability Manager allows the creation of regular unprivileged sub-user accounts which can be allowed to see only selected amount of hosts based on the available restrictive options available in the account configuration.
Synopsis
The following message received by SVM customer illustrates the problem users would often experience when they approach configuration of a specific read-only account with limited visibility:
"I want to add a new user that can only see the computers for his department in CSI (Software Vulnerability Manager). When I added him initially he saw the All Hosts smart group. And when I added the filter to specific clients he can't see any hosts at all.
Am I reading the limitations wrong?
Is there any way to disable the visibility of the "All hosts" group in the SVM interface? Can I see only the hosts I restricted my sub-account to? We want to create a user that has the following abilities:
1. No admin rights for the user
2. Restriction to see only the hosts or specified on the account.
3. The all hosts smart group, all software All Advisory. should not be visible"
Discussion
Such configuration is possible in the Software Vulnerability Manager and it is well documented in the online technical user manual of the product. The following sentence explains the correct approach to configuring a sub-account with restrictions applied to individual hosts:
"Please note that Host names must be entered with the langroup(domain) in the format hostname.langroup."
For example, let's take an internal test domain named RD12.LAB
A host named W8 would have its FQDN as W8.RD12.LAB as most people would assume to use.
Here's how you should do it instead in the SVM:
- Use the NetBIOS name of the host
- Use the NetBIOS name of the domain
- Remove the TLD extension (.com/.lab/.anything)
Account Configuration Steps:
- Use the "Restrict to Individual Hosts" option in the new account configuration.
- Therein you should type the hostname as W8.RD12.
- Enable 'Read-Only' and give this account access only to 'Results'
- This will enable it to audit the scan data of the W8.RD12 host.
Use the below screen example to adjust:
Additional Information
Any other configuration different than hostname.langroup would be incorrect, and it would result in different outcomes after you log in with the new sub-account user.
Related Articles
Operators with restricted "Create new licenses from purchased entitlements" right can process Purchases 4Number of Views Can Users Have a Restricted View of the Dashboard? 8Number of Views User interface elements not visible or buttons disappear in IT Visibility 8Number of Views Create a New Windows User with an MSI Installer without user input. 4Number of Views Operators with restricted "Configure software asset properties" can view the License setting, under System Settings 4Number of Views
Hi, I am Reva - Ask me anything.
No new updates
Thanks for the feedback!
Your feedback has been saved.Rate this response:
Add Additional feedback ( Optional )
Are you sure you want to cancel
the case creation?
Are you sure you want to cancel the case creation?
Are you sure you want to close this case
| Products | Region | Phone Numbers |
|---|---|---|
| FlexNet Operations FlexNet Embedded FlexNet Publisher FlexNet Connect FlexNet Code Insight InstallAnywhere InstallShield |
North America * |
+1 630-332-2513 (toll) +1 877-279-2853 (toll-free in North America) |
| Europe * |
+44 1925 944367 (toll) +44 800 047 8642 (toll-free in Europe) |
|
| Japan * | +81 3-4540-5335 (select option 2) | |
| Australia * |
+61 3 9895 2177 +61 1800 560 603 (toll-free in Australia) |
|
|
Usage Intelligence (formerly
Revulytics) Compliance Intelligence |
Please use the Case Portal to submit your support ticket or reach out to your Revenera contact. | |
Case id: 00001065
Activity: Status change: 2 hours ago