Cisco Cisco Firepower Management Center 2000

Seite von 1844
 
48-62
FireSIGHT System User Guide
 
Chapter 48      Managing Users 
  Managing User Role Escalation
Help Menu
License: 
Any
The Help menu and its permissions are accessible to all user roles. You cannot restrict Help menu 
options.
Managing User Role Escalation
License: 
Any
You can give custom user roles the permission, with a password, to temporarily gain the privileges of 
another, targeted user role in addition to those of the base role. This allows you to easily substitute one 
user for another during an absence, or to more closely track the use of advanced user privileges.
For example, a user whose base role has very limited privileges may escalate to the Administrator role 
to perform administrative actions. You can configure this feature so that users can use their own 
passwords, or so they use the password of another user that you specify. The second option allows you 
to easily manage one escalation password for all applicable users. For more information, see 
Note that only one user role at a time can be the escalation target role. You can use a custom or predefined 
user role. Each escalation lasts for the duration of a login session and is recorded in the audit log.
For more information on configuring and using this feature, please see the following sections:
  •
  •
  •
Configuring the Escalation Target Role
License: 
Any
You can assign any of your user roles, predefined or custom, to act as the system-wide escalation target 
role. This is the role to which any other role may escalate, if it has the ability.
To configure the escalation target role:
Access: 
Admin
Step 1
Select 
System > Local > User Management
.
Delete Other Users’ Scheduled Tasks
yes
no
no
no
no
Import/Export
yes
no
no
no
no
Discovery Data Purge (Defense Center only)
yes
no
no
no
yes
Whois
yes
yes
no
no
yes
Table 48-11
System Menu (continued)
Menu
Admin
Maint 
User
Network 
Admin
Security 
Approver
Security 
Analyst