If you have any questions, please contact: aha.support@ts.fujitsu.com
Es wäre hilfreich, wenn der SSO User nach dem iRMC Login kein reiner lesender User ist. Zumindest einige unkritische Dinge, wie z.B. iRMC Reboot, Lizenzschlüssel hinzufügen, Backupdateien sichern, ... sollten möglich sein ohne Userwechsel. - Evtl. mit einem vorgeschaltetem PopUpFenster ala "Wollen Sie das wirklich tun." ;-)
From our perspective, allowing additional permissions to SSO users through exception handling (e.g., permitting selected operations such as reboot or licese handling outside of the defined role) would introduce security risks.
Instead, it is more appropriate to control permissions through proper role design using AD/LDAP group mapping. This approach keeps the model clean, predictable and aligned with standard RBAC practices.
Therefore, we discussed it with engineering and agree to set this request to “Will not be implemented.”
Hello, thank you for providing this request.
From the conception of ISM user permission this request will affect the security rules if we allow a roll over via such a popup. We recommend the usage of LDAP/AD User Management to provide specific Users additional permissions.