Assign/remove users and groups to/from roles
To assign or remove Windows users or groups or basic users to/from a role:
Expand Security and select Roles. Then select the required role in the Overview pane:
In the Properties pane, select the Users and Groups tab at the bottom.
Click Add, select between Windows user or Basic user.
Assign Windows users and groups to a role
Select Windows user. This opens the Select Users, Computers and Groups dialog box:
Verify that the required object type is specified. If, for example, you need to add a computer, click Object Types and mark Computer. Also verify that the required domain is specified in the From this location field. If not, click Locations to browse for the required domain.
In the Enter the object names to select box, enter the relevant user names, initials, or other types of identifier which Active Directory can recognize. Use the Check Names feature to verify that Active Directory recognizes the names or initials that you have entered. Alternatively, use the "Advanced..." function to search for users or groups.
Click OK. The selected users/groups are now added to the Users and Groups tab's list of users who you have assigned the selected role. You can add more users and groups by entering multiple names separated by a semicolon (;).
Assign basic users to a role
Select Basic User. This opens the Select Basic Users to add to Role dialog box:
Select the basic user(s) that you want to assign to this role.
Optional: Click New to create a new basic user.
Click OK. The selected basic user(s) are now added to the Users and Groups tab's list of basic users who you have assigned the selected role.
Remove users and groups from a role
On the Users and Groups tab, select the user or group you want to remove and click Remove in the lower part of the tab. You can select more than one user or group, or a combination of groups and individual users, if you need to.
Confirm that you want to remove the selected user(s) or and group(s). Click Yes.
Note
A user may also have roles through group memberships. When that is the case, you cannot remove the individual user from the role. Group members may also hold roles as individuals. To find out which roles users, groups, or individual group members have, use the View Effective Roles function.
Example role distribution
Organizations can define two, three, or more user roles depending on their operational and security requirements. The following example illustrates how responsibilities can be distributed using role-based access control.
Administrators
Administrators have full access to system settings, configuration, and user management. They are responsible for installing, configuring, maintaining, and upgrading the system, as well as managing user accounts and permissions.
Typical responsibilities include:
System configuration
User management
System upgrades
Engineers
Engineers are responsible for maintaining and troubleshooting devices and system infrastructure. They have access to diagnostic and maintenance functions but do not manage users or system-wide security settings.
Typical responsibilities include:
Device maintenance
Diagnostics and troubleshooting
System health monitoring
Reporting
Operators
Operators monitor the system and respond to operational events. They can view live and recorded video, manage alarms, and perform other day-to-day monitoring tasks, but cannot change system configuration.
Typical responsibilities include:
Live monitoring
Playback and investigation
Exporting evidence
Alarm handling