Role-Based Access Control (RBAC)

A role is a set of permissions that defines what an administrator or a network user can do, such as viewing data or making configuration changes. Roles determine the level of access to the portal, from having full read/write access (Administrator), to read-only access (View Only) or limited write access (Operator, Guest Operator). Roles can control access to specific network resources by providing permission to view and edit resources.

RBAC, Identity, and Access are managed in the HPE GreenLake portal. For more information about managing users and roles in the HPE GreenLake portal, see the IAM section in the HPE GreenLake Cloud User Guide.

Built-in Roles

Built-in roles are predefined roles with permissions already assigned to the platform or services they apply to. These roles cannot be edited or deleted. HPE Aruba Networking Central supports the following pre-defined roles which can be assigned to users through the HPE GreenLake platform.

Note:
  • To access HPE Aruba Networking Central, it is recommended that you have built-in roles. If custom roles are used, users may not observe behavior consistent with the assigned role permissions for applications.

  • Central NAC does not support RBAC custom roles.

Table 1: Built-in Roles

Role

Privilege

Aruba Central Administrator

Administrator for HPE Aruba Networking Central. Has complete access to all the resources and has no restrictions.

Aruba Central View Only

Has view only access to HPE Aruba Networking Central. Has view and execute access to the troubleshooting tools in HPE Aruba Networking Central.

Aruba Central View Edit role

Has complete access to all the resources and has no restrictions.

Aruba central Guest Operator

Has limited access to HPE Aruba Networking Central. Has edit and view access to the visitor widget in Central NAC.

Aruba Central Operator

Has view access to HPE Aruba Networking Central. Has edit and view access to the troubleshooting tools in HPE Aruba Networking Central.

Scope Groups (Resource Restriction Policy Support)

HPE GreenLake allows you to create custom scope group to restrict user role permission in HPE Aruba Networking Central. When assigning a role to a user, you can restrict the permission to a set of scope group.

In HPE Aruba Networking Central, scopes refer to Sites, Site Collections, and Device Groups. Custom scope group support allows you to control which Sites, Site Collections, and Device Groups a user can access. Using this custom scope group support, you can restrict permissions for the applications based on the scope that you are defining when you assign the user role. For more information, see the Workspace identity & access section in the in HPE GreenLake Cloud User Guide.

Note:

A scope group can include both Classic Central scopes (Groups) and HPE Aruba Networking Central scopes (Sites, Site Collections, and Device Groups). However, any HPE Aruba Networking Central group added under Classic Central groups will not appear in HPE Aruba Networking Central unless it is explicitly added as a HPE Aruba Networking Central scope, such as by assigning it under Device Groups.

Configuring SAML SSO

The HPE GreenLake cloud SAML attribute, hpe_ccs_attribute, defines the service access assigned to each user. Create the hpe_ccs_attribute on the IdP only if you are using SSO with session-based authentication. If you plan to use SSO for authentication only (static authorization) and manage user access on HPE GreenLake cloud, you do not have to create the hpe_ccs_attribute.

Note:

HPE Aruba Networking Central does not support version_0 as the version of the assertion attribute. You must upgrade to version_1 to access the new hierarchy scopes in HPE Aruba Networking Central.

For more information on managing users and roles in the HPE GreenLake portal, see the IAM section in the HPE GreenLake Cloud User Guide.