Adding LDAP Operators
You can create accounts for operators to access the console by using an existing Active Directory or LDAP account.
username
username@domain
domain\username
- Two-factor authentication with Common Access Cards (CAC), Personal Identity Verification (PIV) cards, or other factors, if required by the Identity Provider.
- Web-based Single Sign-On authentication method from the identity provider login URL.
To add an LDAP operator, complete the following steps:
- Ensure that the needed Active Directory or LDAP directory is added to the BigFix environment.
- Click the Tools > Add LDAP Operator menu item or right click in the work
area and then select Add LDAP Operator. The Add LDAP User dialog appears.
- You can query and filter the users defined on the specified LDAP server using the Search field and the two radio buttons.
- When you find the user to add as LDAP operator, select it and click Add.
The Console Operator panel opens.
- From the Details tab assign operator permissions.
You can decide to give the operator the ability to trigger restart and shutdown as Post-Action or to include them in BigFix Action Scripts. Depending on the configuration that you set for a specific operator for shutdown and restart, the radio button in the Post Action tab of the Take Action panel might be disabled for that operator. This configuration has no effect on actions with action script type other than BigFix Action Script.
You can also set permissions to access the BigFix Console and REST API.
- The Administered Computers tab lists the computers managed by this operator.
- From the Assigned Role tab, select the roles that you want to assign or unassign this operator to.
- From the Sites tab, assign the sites that you want this operator to have access to or unassign them.
- From the Computer Assignments tab, specify the properties that must be matched by the computers that the operator can manage.
- To save the changes click Save Changes.
At any time, you can also convert a local operator to an LDAP operator. To do this, follow these steps:
- From any list of local operators, right click on the operator you want to convert.
- From the context menu, select Convert to LDAP Operator.