Cisco Cisco Email Security Appliance C170 Guia Do Utilizador

Página de 1211
 
32-11
AsyncOS 9.1.2 for Cisco Email Security Appliances User Guide
 
Chapter 32      Distributing Administrative Tasks
  Managing Custom User Roles for Delegated Administration
View all, edit assigned: Delegated administrators can view all mail policies and content filters on 
the appliance, but they can only edit the ones assigned to the custom user role.
View all, edit all (full access): Delegated administrators have full access to all of the mail policies and 
content filters on the appliance, including the default mail policies, and have the ability to create new 
mail policies. Delegated administrators can modify the senders, recipients, and groups of all mail 
policies. They can also reorder mail policies. 
You can assign individual mail policies and content filters to the custom user role using either the Email 
Security Manager or the Custom User Roles for Delegated Administration table on the User Roles page.
See 
 for information on using the Custom 
User Roles for Delegated Administration table to assign mail policies and content filters.
DLP Policies
The DLP Policies access privileges define a delegated administrator’s level of access to the DLP policies 
via the DLP Policy Manager on the Email Security appliance. You can assign DLP policies to specific 
custom user roles, allowing delegated administrators, in addition to operators and administrators, to 
manage these policies. Delegated administrators with DLP access can also export DLP configuration 
files from the Data Loss Prevention Global Settings page. Only administrators and operators can change 
the mode of DLP used from RSA Email DLP to RSA Enterprise Manager, and vise versa.
If a delegated administrator also has mail policy privileges, they can customize the RSA Email DLP 
policies. Delegated administrators can use any custom DLP dictionary for their RSA Email DLP 
policies, but they cannot view or modify the custom DLP dictionaries.
You can assign one of the following access levels for RSA Email DLP policies to a custom user role:
No access: Delegated administrators cannot view or edit RSA Email DLP policies on the Email 
Security appliance.
View assigned, edit assigned: Delegated administrators can use the DLP Policy Manager to view 
and edit the RSA Email DLP policies assigned to the custom user role. Delegated administrators 
cannot rename or reorder DLP policies in the DLP Policy Manager. Delegated administrators can 
export DLP configurations.
View all, edit assigned: Delegated administrators can view and edit the RSA Email DLP policies 
assigned to the custom user role. They can export DLP configurations. They can also view all RSA 
Email DLP policies that are not assigned to the custom user role but they cannot edit them. 
Delegated administrators cannot reorder DLP policies in the DLP Policy Manager or rename the 
policy.
View all, edit all (full access): Delegated administrators have full access to all of the RSA Email 
DLP policies on the appliance, including the ability to create new ones. Delegated administrators 
can reorder DLP policies in the DLP Policy Manager. They cannot change the DLP mode that the 
appliance uses.
You can assign individual RSA Email DLP policies to the custom user role using either the DLP Policy 
Manager or the Custom User Roles for Delegated Administration table on the User Roles page.
See 
 for more information on RSA Email DLP policies and the DLP 
Policy Manager.
See 
 for information on using the Custom 
User Roles for Delegated Administration list to assign RSA Email DLP policies.