Managing Users
A user is a person who has active IP Telephony services. Cisco Prime Collaboration Provisioning allows you to add users, synchronize user information, reapply the services, update user information, and domain specific user roles.
The user role refers to the role that a user will have within an organization. This role dictates the services to which the user is entitled. User roles are predefined in the system.
Note |
|
Adding Users
Note |
To create a new user retaining the user information during system reboot, refer the following steps. |
To add users:
Procedure
Step 1 |
Choose User Provisioning. |
||
Step 2 |
In the User Provisioning page, click Add. |
||
Step 3 |
In the Add User window, if you want to add user click User radio button, else click Open Space radio button, and enter the User ID, Domain, and Name. Also, enter values for other fields if required. Expand the Additional Settings pane to enter location and contact details. To launch quick view for a particular domain or user role, while selecting the domain and user role, click the drop-down menu and rest the mouse on quick view icon.
|
||
Step 4 |
In the Save and Begin Provisioning drop-down:
|
Cross-launching Related Links in Unified Communications Manager and Unity Connection from User Provisioning
Cisco Prime Collaboration Provisioning allows an administrator to cross launch Manager configuration and Assistant configuration for a selected user. As an administrator, you can cross-launch Related Links Pages for Users, Endpoints and Lines from Cisco Prime Collaboration Provisioning. When you cross-launch the Manager configuration and Assistant configuration, you can access the UI and perform any operation directly on the server. Using Single Sign-On, you can cross launch to a few of the applications.
If the Voicemail service is provisioned for the user, the cross-launch links from the Voicemail service: Notification Devices, Alternate Extensions, Greetings, Private Lists.
Rest your mouse pointer over User Services in the Service Details page ( select a user), and click the quick view icon to view the Manager configuration and Assistant configuration cross launch link.
Moving a Single User
Before you begin
Ensure the following before performing a single user move:
-
You must have administration privileges to perform this task.
-
User can be moved from one domain to another irrespective of the service area, provided they belong to the same call processor.
-
User can be moved from one service area to another provided they belong to the same domain and call processor.
-
Users cannot be moved unless they are on the same cluster. Users cannot be moved between clusters.
To move a single user from one domain to another:
Procedure
Step 1 |
Choose User Provisioning. |
||||
Step 2 |
In the User Provisioning page, select a user and click Move. Move User window appears with options for single user move. |
||||
Step 3 |
Select a new domain from the New Domain drop-down list, where the user will be moved. |
||||
Step 4 |
Select the service area from the New Service Area drop-down list. This drop-down will list the service areas in a domain based on the services that are configured for a user. For example, if a user has voice mail service enabled, service areas that are not associated with the Cisco Unified Communications Manager will not be listed in this drop-down. |
||||
Step 5 |
Click Apply to All Services to apply all services to the new service area. If you want to update the services with new settings, you can still select a service and choose a new service area and service template for a particular service. Check the Keep Service Area and Template Settings check box to apply the service area attribute settings alone to the selected service.
|
||||
Step 6 |
Save the settings and click Move User to initiate the single user move. Once the move is successful, a new order is created for that user.
|
Moving Bulk Users
Before you begin
Ensure the following before performing bulk user move:
-
You must have administration privileges to perform this task.
-
All users selected for bulk move must be from the same domain and cluster.
-
Bulk move cannot be performed for multiclustered users.
To move a bulk of users from one domain to another:
Procedure
Step 1 |
Choose User Provisioning. |
||||
Step 2 |
In the User Provisioning page, select users and click Move. Bulk Move window appears. |
||||
Step 3 |
Select a new domain from the New Domain drop-down list, where the user will be moved. |
||||
Step 4 |
Select the service area from the New Service Area drop-down list. |
||||
Step 5 |
Select the Endpoint Settings and Line Settings if you want to configure new service area settings along with the move. This is an optional step. Skipping this step will move the users to a new service area with the existing service area settings. |
||||
Step 6 |
Click Move User to initiate the bulk move. Once the move is successful, a new order is created for that user.
|
Importing Users Using a Text File
Cisco Prime Collaboration Provisioning enables you to import multiple users in a single operation in the following ways:
-
Using a file in text (TXT) format
-
Using an LDAP server
For information on adding individual users, see Adding Users.
To import users using a text file:
Procedure
Step 1 |
Click User Provisioning > Import Users. |
||
Step 2 |
In the Import User dialog box, click the From File radio button. |
||
Step 3 |
Click Browse and select the user import file. You can also download the sample import file available in the Import Users dialog box for your reference. You can edit the sample file (.txt ) using Excel, save the updated spreadsheet as tab-delimited text file, and import the file. OrderType, UserID, LastName, and Domain are mandatory fields (rest of the fields are not mandatory; you can leave them blank). If you want to enable auto-provisioning for a user, you must set the DoNotAutoProvisionServices field to "False". Also, you must provide the values for Auto-Provisioning ServiceArea and Auto-Provisioning Line Type fields. If you have selected the Line Type as Chosen Line, you must provide the value for Auto-Provisioning Directory Number field.
|
||
Step 4 |
Click Import. The Import button remains disabled, till you select a file for import. After you click the Import button, the import status of the file will be displayed in the Import Users page. To see the import status of the previously imported file, click View Last File Import Status. Cisco Prime Collaboration Provisioning creates the users based on the details provided in the file. If Auto-provisioning is enabled (set to True), Cisco Prime Collaboration Provisioning will automatically provision the default services for the users based on the Auto-provisioning parameters provided in the uploaded file. |
Importing Users From an LDAP Server
To import users from an LDAP server:
Procedure
Step 1 |
Click User Provisioning > Import Users. |
||
Step 2 |
In the Import User dialog box, click the From LDAP radio button. |
||
Step 3 |
Select the domain. |
||
Step 4 |
Click Import. To view the latest LDAP synchronization report, click View Last LDAP Sync Report
See Configuring LDAP Server Synchronization for more information. |
Exporting Users
Cisco Prime Collaboration Provisioning enables you to export users along with their user information. However, you cannot export the services provisioned for the user.
Note |
The Export Users button is enabled when you select one or more users. |
To export users:
Procedure
Step 1 |
On the User Provisioning page, select the number of users that you want to export. |
Step 2 |
Click Export Users. A tab-separated data text file is generated. This file contains details of the exported users. You can import the exported users using the Import Users button. |
Managing User Passwords
You can change the password, reset to default, or prompt users to change their password after their initial login to the application. You must have the correct privileges to manage passwords.
You can update the following:
-
Provisioning login password
-
Cisco Unified Communications Manager password
Note
The Cisco Unified Communications Manager password cannot be modified when the Cisco Unified Communications Manager is configured to use external authentication. Cisco Prime Collaboration Provisioning indicates that the password is updated, although it is not.
-
Cisco Unified Communications Manager PIN
-
Cisco Unified Communications Manager Express password
-
Cisco Unity Subscriber password
-
Cisco Unity Connection PIN
-
Cisco Unity Connection Web password
When resetting the Cisco Unity Connection Web password, if the new password is not of required length, the following error occurs:
Unity Connection Password: Failed to reset credential: The credential minimum length check failed. Minimum length = 8
- Unified CM MLPP Password
This password can be changed using the Manage PIN/Password option only when you set the MLPP User Identification Number and MLPP Precedence Authorization Level for User Service (on the Service Provisioning page).
The Cisco Prime Collaboration Provisioning login password must be a combination of at least three of the following:
-
Uppercase letters
-
Lowercase letters
-
Numbers
-
Special characters
You can either change or reset the password to the Provisioning system default, or prompt the user to change their password when they log in to the application next time. You can obtain the default values for the user passwords from your Provisioning administrator, Managed Service Provider, or corporate IT department.
The following rules control the default passwords:
-
DefaultCUPMPassword
-
DefaultCallManagerPassword
-
DefaultCallManagerPIN
-
DefaultCallManagerDigestCredentials
-
DefaultUnitySubscriberPassword
-
DefaultWebAccessPassword
For more information about rules, see Overview of Business Rules.
Note |
After you reset the password of a user, you must inform the user of the default value that is required to change their password. |
To change, reset password, or prompt users to change their password the next time they log in to the application:
Procedure
Step 1 |
Open the Manage User page for the desired user (see Adding Users). |
Step 2 |
Click Manage Passwords. |
Step 3 |
On the Password Management page, you can select Password, PIN, or Digest Credentials to modify. Select the password to be changed from the drop-down list. |
Step 4 |
Do one of the following:
|
Step 5 |
Click Done to confirm. |
-
Password cannot be the same as, or reverse of, the username.
-
Password cannot have a character repeated consecutively more than three times.
-
Password cannot be:
-
Cisco or the reverse.
-
Cisc0 (with zero substituted for o).
-
C!sco (with exclamation mark substituted for i).
-
Ci$co (with dollar sign substituted for s).
-
Any variation of the previous that uses variations in case (uppercase or lowercase).
-
-
Password must have lowercase, uppercase, special characters, and digits.
-
The minimum number of characters required is eight (by default, but can be changed).
-
The maximum number of characters allowed is 127 (default is 80 characters).
-
The password must contain characters from three of the following four character sets: lowercase, uppercase, number, and special character. The number of character sets is configurable (Default is three).
-
The minimum number of characters required is six (Default is eight, but can be changed).
-
Allows re-use of password after <number of> changes (minimum is 0, maximum is 24, and default is 0). This setting enables the user to reuse an existing password after the specified number of password change instances. For example, If the value is set as 0, the user can reuse the same password immediately. If the value is set as 10, the user can reuse the current password after the next ten instances of password changes, that is, if the current password is xyxy, this password can be reused after the next ten password changes.
-
Password can only be changed after <number of> hours (minimum is 0, maximum is 48, and default is 0). If the value is set as 0, the user can change the password immediately. If the value is set as 24, the user can change the password after 24 hours since change of the last password.
-
Password expires after <number of> days (minimum is 0, maximum is 365, and default is 0). This setting notifies the user that the password is expiring in "x" number of days and the account is disabled if the password is not changed within the specified timeframe. For example, if the value is set as 0, the password never expires.
-
Show warning message <number of> days before expiration (minimum is 0, maximum is 31, and default is 0). This setting indicates when the user is notified about password expiration. For example, if the value is set as 0, this setting is disabled, and no warning message is displayed about expiration of the password. If the value is set as 5, a warning message is displayed five days before the expiration of the password.
-
Prompt for confirmation <number of> days before expiration (minimum is 0, maximum is 30, and default is 0). This setting indicates when the user has to be prompted about expiration and changing of the password. When prompted, the user has to either acknowledge the password expiry or proceed to change the password. For example, if the value is set as 0, this setting is disabled, and no confirmation prompt is displayed about expiration or change of the password. If the value is set as 3, the user is prompted to change the password three days before the expiration of the password.
Cisco Prime Collaboration Provisioning stores the password policy properties in a file named passwordpolicy.properties under opt/cupm/sep. You can modify the properties file to change the password policies as required. Restart Cisco Prime Collaboration Provisioning whenever you modify the password policies.
Although Cisco Unified Communications Manager Express allows a user to have only one associated endpoint, Cisco Prime Collaboration Provisioning overcomes this limitation, allowing more than one endpoint to be associated to the user.
In Cisco Unified Communications Manager Express, new users are created with the same username appended with a tilde (~) and sequence index (starting with 1) from the second and subsequent endpoints (for example, TestUser and TestUser~1). Use the exact username to view the corresponding endpoint details in the Cisco Unified Communications Manager Express web interface.
When you change the password in Cisco Prime Collaboration Provisioning, the password is changed for all the corresponding user names in Cisco Unified Communications Manager Express.
Resetting User Password Using Forgot Password Link
For Cisco Prime Collaboration Release 11.6 and later
To reset your password using Forgot password? link in the login page:
Procedure
Step 1 |
Click Forgot password? link in the login page. |
||
Step 2 |
Enter your User ID and click Send Email.
|
||
Step 3 |
Click the link in the password reset email to initiate the password reset request. |
||
Step 4 |
Enter your new password and click Change Password. |
Recovering User Password
For Cisco Prime Collaboration Release 11.6 and later
When you log in, you are prompted to configure the password recovery. Click Yes to set the recovery email ID, otherwise click No to return to the Home page.
To configure the password recovery:
Procedure
Step 1 |
Choose Password tab. and click |
Step 2 |
Do one of the following:
|
Step 3 |
Click Update. |
Synchronizing a User
The data of a user in Cisco Prime Collaboration Provisioning is synchronized with the user data in the Call Processor and Unity Connection. For more information about synchronizing, Synchronizing Domains.
When synchronizing users, remember the following:
-
The username and phone number fields may display Unknown for users who were initially created on Cisco Unified Communications Manager Express and then later synchronized to Cisco Prime Collaboration Provisioning.
You can update the user information through Cisco Prime Collaboration Provisioning, but be aware that this information will be pushed to the Cisco Unified Communications Manager Express system, and will overwrite any existing information for the user in the ephone description field.
-
If a Cisco Unified Communications Manager Express is the only device present in a Domain and Service Area, during Domain synchronization users are not created in Cisco Prime Collaboration Provisioning if the ephone username command is not configured in Cisco Unified Communications Manager Express.
Ensure that the ephone username command is configured in Cisco Unified Communications Manager Express for all users.
-
For Cisco Unified Communications Manager Express, when using the button command in ephone configuration mode, ensure that you only use a colon (:) as the separator. Cisco Prime Collaboration Provisioning only supports a colon as a separator in the button command. If any other separator is used, Cisco Prime Collaboration Provisioning does not display the line in the User Record Details page. Only the endpoint is displayed.
Procedure
Step 1 |
Choose User Provisioning. |
||
Step 2 |
From the list of users, mouse over QuickView, and click Synchronize User.
|
Overview of Authorization Roles
For Cisco Prime Collaboration Release 11.2 and earlier
Two types of Provisioning user roles are available: global and domain specific. Based on their roles, Provisioning users are authorized to perform various tasks in Provisioning. In the example below, the Domain administrators have administrative privileges for a specific domain. They can set polices and rules for the domain assigned to them. The multi-domain administrators have privileges for more than one domain. The global administrators have access to all Provisioning functionality.
When you attach a Provisioning server with existing user data, then the globaladmin and domain-admin roles are synchronized automatically in the User Management page.
Note the following:
-
Activity roles are available in Cisco Prime Collaboration Provisioning Advanced only. This menu is not available in Cisco Prime Collaboration Provisioning Standard.
-
While creating an order for an endpoint in Cisco Prime Collaboration Provisioning Standard, MAC or dummy MAC address is mandatory.
Apart from global and domain administrator roles, a Provisioning user can also have ordering and activity roles. A provisioning user with an ordering role can place orders for users in a particular domain.
Authorization Role |
Description |
||
---|---|---|---|
Global Roles |
|||
Administration |
Has access to all Provisioning functionality. |
||
Maintenance |
Authorized to configure system cleanup activities. See Maintenance Mode. |
||
Roles for Domain In the drop-down list, select the Domain for which you are setting the authorization roles. The selected roles only apply to the selected Domain. To apply the same authorization role to all available domains, select Apply to all domains.
|
|||
Policy |
Authorized to modify user roles, and add or update endpoint inventory. |
||
Infrastructure Configuration Management |
Authorized to provision infrastructure configuration objects. When you select this role, you must also select a profile from the Permission Profile box. |
||
Permission Profiles |
Sets the permissions for which infrastructure configuration object users assigned this authorization role can configure. (For information on setting permissions, see Managing Infrastructure Configuration Permissions). |
||
SelfCare User |
Authorized to manage his own services; set up lines, manage services, and configure endpoint options quickly and easily.
|
||
Ordering Roles
Users assigned these roles are allowed to place orders for other users and themselves. |
|||
Ordering |
Authorized to:
|
||
Advanced Ordering |
Authorized to access all the functionality specified by the Ordering role; can also access Advanced Order Options in the Order Entry page. |
||
Advanced Assignment |
Authorized to access all the functionality specified by the Ordering role, and to assign the MAC address for an endpoint at the time of order entry. Available in Cisco Prime Collaboration Provisioning Advanced only. |
||
Activity Roles Users assigned one of these roles can perform activities assigned to the group during order processing. |
|||
Approval |
Authorized to accept and complete the approval for orders. |
||
Assignment |
Authorized to accept the user activity for assigning the MAC address. |
||
Shipping |
Authorized to accept and complete shipping of orders. |
||
Receiving |
Authorized to accept and complete receiving of orders. |
Access Control Groups
For Cisco Prime Collaboration Release 11.5 and later
This feature (choose Administration > Access Control) enables you, as an administrator, to create access control groups for granting privileges to users to access specific pages and perform specific operations on them. You can assign and restrict system access to the user by providing granular access. You can grant access rights to the users through the Access Control Group, with which the user can access the features and functions based on the granular control. All authorization roles including ordering, shipping, and maintenance are converted to access control groups if you are upgrading to Cisco Prime Collaboration Provisioning 11.5 and later. In addition, the feature enables you to export and import access control groups in different systems having same versions of Cisco Prime Collaboration Provisioning. The following table lists the default access control groups:
For Cisco Prime Collaboration Release 12.1 and later
-
Logging and ShowTech
-
Data Maintenance
-
Backup Management
-
Updates
-
Schedule Synchronization
-
License Management
-
Single Sign-On
-
Rules
-
Settings
Name |
Description |
---|---|
View Only |
Users who only view domains, service areas, service templates, and user roles |
Administrators |
System Administrator with full access |
Help Desk |
User can place an order without access to advanced setting |
-
Cisco Prime Collaboration Provisioning Standard does not support the creation of a new access control group. However, you can modify existing groups and assign users to groups.
-
You must upload an advanced license (with delegation feature enabled) to create a new access control group. In standard license, delegation feature is disabled by default.
-
You can create up to 1000 groups only.
-
“globaladmin” users have full access and are not assigned to any access control groups.
-
A user can be assigned more than one Access Control Group.
-
A user can be given access to a particular privilege with limited or full access.
-
Some privileges have domain-based restrictions.
-
Each domain can be controlled with different granular access as suitable.
-
Administrator users cannot change or delete the group which they belong, but can change or delete other administrators group.
-
Full access groups can be created only either globaladmin or users with full access privilege. The default administrator group can be edited and deleted too.
-
For the users other than administrator and full access users, Access Control Group table lists the groups which are created with access items other than full access.
-
Buttons and quick view in the respective pages and operations are displayed or hidden based on the granular control.
-
Access Control link in quickview of user provisioning is displayed only if the logged in user is a member of Full Access group or having Access Control privilege (either All or Assign users to groups granular access).
-
Can create access control groups.
-
Can assign users to groups, when the user is assigned a group that has access to access control page with All granular access or Assign users to groups or add group, edit group, delete group, or if the user has full access.
-
Cannot assign or edit or delete himself to any group.
-
Cannot modify the full access privileged users or globaladmin.
Creating Access Control Group
-
Add/Edit/Delete/Import/Move users in User Provisioning page—The user who is assigned with Add/Edit/Delete/Import/Move access can view the relevant buttons.
For Cisco Prime Collaboration Provisioning release 12.5 and later: The available options are Add/Edit/Delete/Import/Export/Move
-
View the configuration information of devices—The user who is assigned with read-only access can only view the relevant information.
-
Create a group with a unique name and add members to the group.
-
Under Privileges section, click Add.
-
From the Name drop down in the dialog box, select User Provisioning.
-
Select the domains from the Accessible Domains check box as suitable.
-
Select the Access check box and the relevant details as suitable.
-
Click Save.
For Cisco Prime Collaboration Provisioning release 12.5 and later: The available options are Add/Edit/Delete/Import/Export/Move
-
Select the group you have already created.
-
Under Privileges section, click Add.
-
From the Name drop down in the dialog box, select Device Setup.
-
Select Read-Onlyfrom the Access check box.
-
Click Save.
Operations of Access Control Group
Operation |
Description |
---|---|
Add |
To add a new Access Control Group
|
Edit |
To modify an existing Access Control Group
|
Delete |
To remove an existing Access Control Group
|
Copy |
Creating a new group by copying Privilege from an existing group
|
Export |
To export the groups to a tsv file
|
Import |
To import the exported groups into a different Cisco Prime Collaboration Provisioning Server
|
Quick View |
Hovering over Quick View displays the details of the group, including the members and the access list items. |
Note |
Changes to your access control group(s) or privilege(s) invalidates your session and you are logged out. This happens if you perform the following operations:
|
Privileges with Granular Control
Privilege Name |
Description |
Granular Access |
Domain Control |
---|---|---|---|
Full Access |
Relates to users who have all the access permissions in Cisco Prime Collaboration Provisioning. |
All |
NA |
Access Control |
Enables you, as an administrator, to configure roles, access control groups, and access privileges for roles. |
|
NA |
Device Setup |
Enables you to add or edit or delete UC devices to Cisco Prime Collaboration Provisioning. |
All, Read-Only |
NA |
User Provisioning |
Enables you to add or edit or delete or import users, and provision services. |
|
Yes |
Provisioning Setup |
Enables you to set up all your user provisioning tasks such as adding and configuring Domains, Service Areas, User Roles, and, Service Templates. |
All, Read-Only |
No |
Infrastructure Configuration |
Enables you to view, add, edit, or delete the configuration settings of a Call Processor and Unified Message Processor. |
All, Read-Only |
Yes |
Provisioning History |
Enables you to search and view the status of an order. |
All, Read-Only |
Yes |
Dashboard |
Enables you to manage the real-time information about the operational status of your processor, device, domain, and users. |
All, Logged In Users, Locked Users |
NA |
Manage Endpoints |
Enables you to upload new and existing endpoints through the user interface. |
All |
Yes |
Manage Directory Numbers |
Enables you to store and manage directory numbers that are associated with each Service Area in the Provisioning inventory. |
All |
NA |
Inventory Search |
Enables you to browse and search the Provisioning inventory. |
All |
NA |
Unified Communication Services |
Lists the Unified Communication services. |
All |
NA |
Getting Started Wizard |
Ability to run the Getting Started Wizard. |
All |
NA |
Activities |
Enables you to view all the order-related activities, including System Activities. |
All |
Yes |
Reports |
Enables you to view details on Service Area, Endpoint Inventory, DNB, Audit Trial, and so on. |
All |
NA |
Audit Trail |
Enables you to view details about the user login or logout, password, account, and timeout. |
All |
NA |
License Management and Single Sign-On |
Enables you to add or import or delete licenses, and enable SSO in Cisco Prime Collaboration Provisioning to cross-launch the UC applications. |
All |
NA |
Rules and Settings |
Supports predefined business rules and allows you to manage Analog Endpoints, Password Policy, self-care feature access, FIPS and custom settings. |
All |
NA |
Logging and ShowTech |
Enables you to view and download application log files. |
All |
NA |
Maintenance and Backup |
Enables you to put Cisco Prime Collaboration Provisioning into maintenance mode as well as backup your data, and restore it. |
All |
NA |
Updates and Support |
Enables you to view and add endpoint bundles, localization languages, and SSL certificates. |
All |
NA |
Schedule Synchronization |
Enables you to synchronize Call Processors, Message Processors, Presence Processors, Active Directories, and Domains. |
All |
NA |
Authorization Roles After Upgrade
For Cisco Prime Collaboration Release 11.5 and later
The following table maps the existing authorization roles with the granular access that the users have after upgrading to Cisco Prime Collaboration 11.5 and later.
Existing Role |
Description |
Before Upgrade |
After Upgrade |
||
---|---|---|---|---|---|
Accessible Pages |
Granular Access |
Accessible Pages |
Granular Access |
||
Administration |
Has access to all Provisioning functionality. |
All Pages |
All |
All Pages |
All |
Maintenance |
Authorized to configure system cleanup activities. See Maintenance Mode. |
Dashboard |
Pending Order Status |
Dashboard |
Welcome page |
Maintenance |
All |
||||
Data Maintenance |
All |
Backup Management |
All |
||
Data Maintenance |
All |
||||
Policy |
Authorized to modify user roles, and add or update endpoint inventory. |
Manage Endpoints |
All |
Manage Endpoints |
All |
Dashboard |
Pending Order Status |
Dashboard |
Welcome page |
||
Provisioning Setup |
Access only to user roles of assigned domains |
Provisioning Setup |
Access to domains, service areas, service templates, and user role of all the domains |
||
Infrastructure Configuration Management |
Authorized to provision infrastructure configuration objects. When you select this role, you must also select a profile from the Permission Profile box. |
Dashboard |
Pending Order Status |
Dashboard |
Welcome page |
Infrastructure Configuration |
All |
Infrastructure Configuration |
All |
||
Ordering |
Authorized to:
|
Dashboard |
|
Dashboard |
Pending Order Status |
User Provisioning |
|
User Provisioning |
|
||
Provisioning History |
All |
Provisioning History |
All |
||
Advanced Ordering |
Authorized to access all the functionality specified by the Ordering role; can also access Advanced Order Options in the Order Entry page. |
Dashboard |
|
Dashboard |
Pending Order Status |
User Provisioning |
|
User Provisioning |
|
||
Provisioning History |
All |
Provisioning History |
All |
||
Advanced Assignment |
Authorized to access all the functionality specified by the Ordering role, and to assign the MAC address for an endpoint at the time of order entry. Available in Cisco Prime Collaboration Provisioning Advanced only. |
Dashboard |
|
Dashboard |
Pending Order Status |
User Provisioning |
All buttons and all actions in quick view with assignment |
User Provisioning |
All buttons in User Provisioning and all actions in quick view with assignment |
||
Provisioning History |
All |
Provisioning History |
All |
||
Approval |
Authorized to accept and complete the approval for orders. |
Dashboard |
Pending Order Status |
Dashboard |
Welcome page |
My Activities |
Approval or Assignment or Shipping or Receiving of pending orders of the assigned domains |
Activities |
All (Approval, Assignment, Shipping and Receiving) of the assigned domains |
||
Assignment |
Authorized to accept the user activity for assigning the MAC address. |
Dashboard |
Pending Order Status |
Dashboard |
Welcome page |
My Activities |
Approval or Assignment or Shipping or Receiving of pending orders of the assigned domains |
Activities |
All (Approval, Assignment, Shipping and Receiving) of the assigned domains |
||
Shipping |
Authorized to accept and complete shipping of orders. |
Dashboard |
Pending Order Status |
Dashboard |
Welcome page |
My Activities |
Approval or Assignment or Shipping or Receiving of pending orders of the assigned domains |
Activities |
All (Approval, Assignment, Shipping and Receiving) of the assigned domains |
||
Receiving |
Authorized to accept and complete receiving of orders. |
Dashboard |
Pending Order Status |
Dashboard |
Welcome page |
My Activities |
Approval or Assignment or Shipping or Receiving of pending orders of the assigned domains |
Activities |
All (Approval, Assignment, Shipping and Receiving) of the assigned domains |
Configuring Privileges
For Cisco Prime Collaboration Release 11.5 and later
This section details steps to be followed to add or edit or delete the privileges.
Procedure
Step 1 |
Choose Administration > Access Control and enter or select the necessary details such as Group Name, Description, and Members. In the Members drop-down, select the users as suitable. |
||
Step 2 |
Click Add or Edit or Delete in the Privileges pane as suitable. |
||
Step 3 |
Click Selected from Accessible Domains drop-down in the Privilege dialog box and choose the domains you want to access or click All to choose all the domains.
|
||
Step 4 |
Select Access as suitable. |
||
Step 5 |
Click Save. |
Granular Control Support for Access Control Items
The following tables describe the supported granular controls for access control items.
Access Control Item |
Supported Granular Control |
Description |
---|---|---|
Full Access |
Not Applicable |
Other than administrators and the users who are part of the full-access privileged group, Full Access access items are not listed in Name drop-down in the Add Access or Edit Access dialog box. |
Access Control |
|
Other than administrator and full access users, Access Control access items are not listed in Name drop-down in the Add Access or Edit Access dialog box.
|
Device Setup |
|
|
User Provisioning |
All, Read-Only Write >
|
|
Provisioning Setup |
|
|
Infrastructure Configuration |
|
|
Provisioning History |
|
|
Dashboard |
|
|
Access Control Items |
Supported Granular Control |
Description |
---|---|---|
Manage Endpoints |
|
|
Manage Directory Numbers |
|
|
Inventory Search |
|
|
Unified Communication Services |
|
|
Getting Started Wizard |
|
|
Infrastructure Configuration Permissions |
|
|
Activities |
|
|
Reports |
|
|
Audit Trail |
|
|
License Management and Single Sign-On |
|
|
Rules and Settings |
|
|
Maintenance and Backup |
|
|
Updates and Support |
|
|
Schedule Synchronization |
|
|
Accessing User Records for a User
Procedure
Step 1 |
Choose User Provisioning. |
||||||||||||||
Step 2 |
Click a specific user. |
||||||||||||||
Step 3 |
Hover over the quick view icon next to the user in the user record page to view the user information and to perform the actions for the selected user. In the Service Details pane, the quick view of a service displays an Add-on Service (if applicable) for quick provisioning. For example, if an existing service (called as Anchor service) is an endpoint, you can add Line service (called Add-on Service) by hovering over the quick view icon and clicking the plus symbol or the link beside the symbol. The following table lists the Add-on Service available for Anchor Service.
|
Viewing or Logging out Active Sessions
You can view active sessions and log out single or multiple active sessions.
Procedure
Step 1 |
Choose Home > Dashboard > Logged In Users. The Logged In Users page appears, showing the list of active sessions. |
||
Step 2 |
To cancel single or multiple sessions, select the session that you want to end. |
||
Step 3 |
Click Log Out. The selected session and the user are logged out of the server.
|
Using Global Search
You can use the global search field to locate any of the following:
-
User ID
-
Name
-
MAC Address
-
Directory Number
-
DN Description
-
Phone Description
-
VM Alias Name
-
EM Name
To search using the global search field at the top of the view pane:
Procedure
Step 1 |
Go to the search field in the top right corner of the Home page. |
Step 2 |
Select the required option form the Search drop-down list:
|
Step 3 |
Enter valid information. |
Step 4 |
Press Enter to begin the search. You will be taken to the corresponding User Provisioning page if an exact match exists. If more than one match occurs, the system displays all records that matches the search criteria. When you click on a result, you will be redirected to that specific User Provisioning page. |