You can create custom role definitions to control access to all areas of Nerdio Manager. Custom roles define the scope and level of access and can be assigned to users and security groups. Users can access modules in read-only or manage mode.
To create a custom role definition:
-
Navigate to System > RBAC > Definitions.
-
Select New Definition.
-
Enter the following information:
-
Name: Type the custom role's name.
-
Description: Type a description of the custom role.
-
Modules: Select all the applicable modules and modes.
Table 7.
Module
Modes
OBSERVABILITY
Insights
-
Read Only: Provides users with read-only access to the Insights dashboards.
-
Manage
Observability > Advisor > Modeler
-
Read Only
-
Manage
Observability > Advisor > Recommendations
-
Read Only
-
Manage
Observability > Advisor > Rules
-
Read Only
-
Manage
AVD & SESSIONS
Workspaces
-
Read Only
-
Manage
-
Manage hosts: Allow users to manage hosts within assigned host pools.
-
Manage assignments: Allow users to manage assignments within assigned host pools.
-
Manage sessions: Allow users to manage sessions within assigned host pools.
-
Manage power state: Allow users to manage the power state of the sessions within assigned host pools.
-
Manage drain mode: Allow users to manage the drain mode of the sessions within assigned host pools.
-
Run scripted actions: Allow users to run scripted actions within assigned host pools.
-
Console Connect Operator: Allows users to manage Console Connect roles.
Desktop images
-
Read Only
-
Manage
App attach
-
Read Only
-
Manage
Portal
-
Manage
ENDPOINT MANAGEMENT
Intune (Global Roles)
-
Read Only
-
Manage
Intune (Read Only Roles)
-
Read Devices
-
Read Policies
-
Read Applications and App Policies
-
Read Update Rings and Policies
-
Read Scripts
-
Read BitLocker
-
Read Antivirus
-
Read User Experience
-
Read User Groups
-
Read Device Location
-
Read Approvals
Intune (Manage Roles)
-
Manage Devices
-
Manage Devices Privileged
-
Manage BitLocker
-
Manage Antivirus
-
Manage Device Groups
-
Manage User Groups
-
Manage Locate Device
-
Manage Policies
-
Manage Applications and App Policies
-
Manage Update Rings and Policies
-
Console Connect Operator
-
Manage Approvals
-
Manage Scripts
-
Manage Microsoft licenses
Intune > Windows 365
-
Read Only
-
Manage
APP MANAGEMENT (UAM)
UAM > Deployment policies
-
Read Only
-
Manage
UAM > App groups
-
Read Only
-
Manage
UAM > Unified catalog
-
Read Catalog
-
Manage Catalog: Allow users to manage UAM catalogs and perform tasks such as importing and deploying apps.
-
Manage Shell App Parameters: Allow users to manage Shell App parameters.
AUTOMATION
Scripted actions
-
Read Only
-
Manage
Scripted sequences
-
Read Only
-
Manage
Scripted sequences > executions
-
Read Only
-
Manage
Task worker analytics
-
Read Only
-
Manage
STORAGE
Cloud desktops > Storage > Azure Files
-
Read Only
-
Manage
-
Manage Profiles: Allow users to manage FSLogix profiles without the need for an active user session and without the need to provide full control to the file share.
Cloud desktops > Storage > Azure NetApp Files
-
Read Only
-
Manage
Cloud desktops > Storage > Log Analytics
-
Read Only
-
Manage
OPERATIONS
Monitoring
-
Read Only
Logs
-
Read Only
Migrate
-
Read Only
-
Manage
Secure variables
-
Read Only
-
Manage
-
Show Secret
-
-
-
Once you have entered all the desired information, select OK.
Note
From the list of definitions, you can edit or delete a custom role.
For more information, see Role-based Access Control (RBAC) in Nerdio Manager.
Comments (0 comments)