
Description
NAICE supports a role-based access control model (RBAC) that provides flexible and secure management of administrator permissions.
NAICE supports two types of roles:
Local roles — assigned manually to local user accounts.
External roles — assigned automatically to external user accounts based on verification of the user’s membership in groups from an external identity source.
Privileges support five access levels:
- Level 0, No access — the system user has no access to the functionality of the privilege. The corresponding sections are not displayed in the NAICE web interface.
- Level 1, Reading — the system user can view sections associated with the privilege.
- Level 2, Creation — the system user can create entities associated with the privilege’s functionality.
- Level 3, Editing — the system user can edit entities associated with the privilege’s functionality.
- Level 4, Removal — the system user can delete entities associated with the privilege’s functionality.
Each access level includes all permissions of the previous one.
Some privileges, such as those related to monitoring, have a maximum access level of 1.
Adding new roles and assigning roles to administrators is described in the built-in documentation (Users and devices → System users).
Management of administrator password policies is described in the built-in documentation (System settings → Security and access → Password policies).
Sections included in privileges
Sections that do not require privileges
Разделы, управляемые привилегиями
| Privilege | Section | Access restrictions | License level |
|---|
| RADIUS policy | Network access → Policy elements: → Authorization profiles → Allowed protocols → Conditions → Dictionaries → RADIUS session limits | RADIUS session limits: - Access levels 1–3 provide Read-only access
- Management becomes available from level 4
|
BASIC |
Network access: → RADIUS policies | - Access levels 1–3 provide Read-only access
- Management and “
reset counters” become available at level 4
|
Users and devices → Identity management: → Identity sequences |
|
| RADIUS monitoring | Monitoring → RADIUS: → Connections journal → Active sessions | Active sessions: - Access levels 1–3 provide Read-only access
- End the session becomes available at level 4
| BASIC |
| Endpoints | Administration → Identity management: → Endpoints → Endpoint groups | Endpoint groups:
- Creating/deleting endpoint groups becomes available at level 2, and adding/removing endpoints to/from a group becomes available starting at level 3
| BASIC |
Network resources | Users and devices → Network resources: → Devices → Device groups → Device profiles |
|
BASIC |
| TACACS+policy | Device access → Policy elements: → Conditions → TACACS+ command sets → TACACS+ profiles → Dictionaries |
|
TACACS+ module |
Device access: → TACACS+ policies | - Access levels 1–3 provide Read-only access
- Management and
“reset counters” become available at level 4
|
Users and devices → Identity management: → Identity sequences |
|
| TACACS+monitoring | Monitoring → TACACS+: → Connections journal → Accounting |
| TACACS+ module |
| Profiling | Policies → Profiling: → Profiling conditions → Profiling policies → Logical profiles |
Profiling policies:
“Reset counters” becomes available at level 4
|
BASIC |
Policies → Elements: → Dictionaries |
|
| Roles and accounts | Users and devices → System users: → Accounts → Roles |
| BASIC |
| Guest access | Guest portals → Portal management: → Portal builder |
|
ADVANCED |
Users and devices → Identity management: → Identity sequences |
|
Guest users | Guest portals → Portal management: → Guest endpoints → Portal users |
| ADVANCED |
Enterprise users | Users and devices → Identity management: → Network users → Network user groups |
Network user groups:
- Creating/deleting user groups becomes available at level 2, and adding/removing users to/from a group becomes available starting at level 3
| BASIC |
System settings
| System: → Log collectors | “Send test event” becomes available at level 2
| BASIC |
Licensing | - Access levels 0–3 provide Read-only access
- Management and
“reset counters” become available at level 4
|
|
System settings | - Access levels 0–3 provide Read-only access
- Management and
“reset counters” become available at level 4
| BASIC |
System settings → Certificate storage | - Level 1: Read-only access
- Level 2: upload/download certificates
- Level 3: edit certificate name/description
- Level 4: full management, including delete
| BASIC |
External sources | Users and devices → Identity management: → External identification sources | “Check connection” is available starting at level 1- Adding user groups and attributes becomes available at level 2
- Deleting user groups and attributes becomes available at level 3
| BASIC |
| Notification services | Notification gateways: → Notification gateways management | “Send test SMS” becomes available at level 2
| BASIC |
Privilege dependencies
For the system to operate correctly, some privileges require the presence of other privileges:
- RADIUS policies — requires read access to: Network resources, Profiling, Guest access
- TACACS+ policies — requires read access to: Network resources
- Endpoints — requires read access to: Profiling
- Roles and accounts — requires read privileges for: External sources
- Guest users — requires read access to: Guest access
- Guest access — requires read access to: Notification services
- System settings — requires read privileges for: External sources, Notification services
Predefined roles
The system includes the following predefined roles for common usage scenarios:
- Super Admin — full access to all system functionality.
- Network Admin — management of network access.
- Hardware Admin — management of network devices.
- System Admin — system administration.
- Guest Admin — management of the guest network.
- Guest Operator — guest network operations.
- Monitor — monitoring and data viewing.
| Privilege | Super Admin | Network Admin | Hardware Admin | System Admin | Guest Admin | Guest Operator | Monitor |
|---|
| RADIUS policy | 4 | 4 | 0 | 4 | 1 | 0 | 1 |
| RADIUS monitoring | 4 | 4 | 0 | 4 | 4 | 1 | 1 |
| Endpoints | 4 | 4 | 0 | 4 | 0 | 0 | 1 |
| Network resources | 4 | 4 | 4 | 4 | 1 | 0 | 1 |
| TACACS+ policy | 4 | 0 | 4 | 4 | 0 | 0 | 1 |
| TACACS+ monitoring | 1 | 0 | 1 | 1 | 0 | 0 | 1 |
| Profiling | 4 | 4 | 0 | 4 | 1 | 0 | 1 |
| Roles and accounts | 4 | 0 | 0 | 1 | 0 | 0 | 0 |
| Guest access | 4 | 1 | 0 | 4 | 4 | 1 | 1 |
| Guest users | 4 | 4 | 0 | 4 | 4 | 4 | 0 |
| Enterprise users | 4 | 4 | 4 | 4 | 0 | 0 | 0 |
| System settings | 4 | 0 | 0 | 4 | 0 | 0 | 0 |
| External sources | 4 | 1 | 1 | 4 | 0 | 0 | 1 |
| Notification services | 4 | 1 | 0 | 4 | 1 | 1 | 1 |