Cisco Cisco Email Security Appliance C170 Guia Do Utilizador

Página de 1219
 
32-7
Cisco AsyncOS 9.1 for Email User Guide
 
Chapter 32      Distributing Administrative Tasks
  Managing Custom User Roles for Delegated Administration
The l
ast
 command displays which users have recently logged into the appliance. The IP address of 
the remote host, and the login, logout, and total time are also displayed.
Managing Custom User Roles for Delegated Administration
You can design custom user roles and delegate specific responsibilities to users that align with their roles 
within your organization, allowing these delegated administrators access only to the email security 
features they are responsible for and not the system configuration features that are not related to their 
roles. Delegated administration provides more flexible control over your users’ access to the email 
security features on the appliance than the predefined administrator, operator, and help desk user roles. 
For example, you may have users who are responsible for managing mail policies for specific domains 
on the Email Security appliance, but you do not want these users to access the system administration and 
security services configuration features, which the predefined administrator and operator roles grant. 
You can create a custom user role for mail policy administrators who can grant these users access to the 
mail policies they manage, along with other email security features that they can use to manage messages 
processed by these policies, such as Message Tracking and policy quarantines.
Use the System Administration > User Roles page in the GUI (or the 
userconfig
 
-> role
 command in 
the CLI) to define custom user roles and manage the email security features for which they are 
responsible, such as mail policies, RSA Email DLP policies, email reports, and quarantines. For a full 
list of email security features that delegated administrators can manage, see 
. Custom roles can also be created when adding or editing a local user account using 
the System Administration > Users page. See 
 for more information.
mail3.example.com> last
Username  Remote Host  Login Time        Logout Time       Total Time
========  ===========  ================  ================  ==========
admin     10.1.3.67    Sat May 15 23:42  still logged in   15m
admin     10.1.3.67    Sat May 15 22:52  Sat May 15 23:42  50m
admin     10.1.3.67    Sat May 15 11:02  Sat May 15 14:14  3h 12m
admin     10.1.3.67    Fri May 14 16:29  Fri May 14 17:43  1h 13m
shutdown                                 Fri May 14 16:22
shutdown                                 Fri May 14 16:15
admin     10.1.3.67    Fri May 14 16:05  Fri May 14 16:15  9m
admin     10.1.3.103   Fri May 14 16:12  Fri May 14 16:15  2m
admin     10.1.3.103   Thu May 13 09:31  Fri May 14 14:11  1d 4h 39m
admin     10.1.3.135   Fri May 14 10:57  Fri May 14 10:58  0m
admin     10.1.3.67    Thu May 13 17:00  Thu May 13 19:24  2h 24m