HPOM uses Windows group accounts to identify valid users of the product. During the installation, HPOM creates the following two groups, either locally on the management server (if you are performing a workgroup installation), or in the domain for domain installation:
You can also specify different names during the installation, or, instead of having HPOM create them for you, you can also create these groups yourself before or during the installation.
The purpose of these groups is to allow users to access the HPOM console and HPOM resources so that they can perform HPOM administrator or operator tasks. For example, you can add Rosa Galvez, who is not a Windows administrator, to the HP-OVE-ADMINS group so that she can perform HPOM administrator tasks, or add Sean Payne, another HPOM user who is not a Windows administrator, to the HP-OVE-OPERATORS group to perform operator tasks. Local or domain administrators by default cannot access HPOM.
The HP-OVE-ADMINS group by default contains the following members:
After the installation, an HPOM administrator can remove the
installing user from the HP-OVE-ADMINS group by launching the
Tools HP Operations Manager Tools
Cleanup rights of the installing user
tool (OvOWResetOVOWAdminRegKeyRights.exe
). The
installing user and HPOM operators do not have permissions to
execute this tool.
Users classified as HP-OVE-ADMINS can perform the following HPOM administrator functions:
By default, members of the HP-OVE-ADMINS group may not have sufficient rights to deploy, remove, and reinstall packages. Depending on the selected deployment option, the user who initiates the update must have the following privileges:
This option requires the HP-OVE-Deleg-User account to be domain or local administrator on the node.
For this option, members of the HP-OVE-ADMINS group must be domain administrators or members of the local Administrators group on the node.
This option applies to HTTPS agents only. Members of the HP-OVE-ADMINS group can specify the user name and password of an alternate user with local administrator rights on the node.
The HP-OVE-OPERATORS group is initially empty.
Users classified as HP-OVE-OPERATORS can perform all HPOM tasks except those listed under HP-OVE-ADMINS tasks:
As an administrator, after adding a user to the HP-OVE-OPERATORS group, you can further define the rights of that user with the User Roles Editor.
Related Topics: