Users

"Users" refers to all Vulnerability ProtectionDeep Security Manager account holders. Use this section to create, modify, and delete User accounts. From the Users page, you can:

Clicking New () or Properties () displays the User Properties window.

General

General Information

The Vulnerability ProtectionDeep Security Manager comes pre-configured with two Roles: Full Access and Auditor. The "Full Access" Role grants the User all possible privileges in terms of managing the Vulnerability ProtectionDeep Security system such as creating, editing and deleting computers, computer groups, Policies, Rules, etc. The "Auditor" Role gives the User the ability to view all the information in the Vulnerability ProtectionDeep Security system but not the ability to make any modifications except to his personal settings (password, contact information, view preferences, etc.) Roles with various levels of system access rights can be created and modified in the Roles page or by selecting "New..." in the Roles drop-down list.

Sign-In Credentials

Multi-Factor Authentication (MFA)

To enable multi-factor authentication (MFA), click Enable MFA. If MFA is already enabled for this user, you can select Disable MFA to disable it. For details, see Multi-Factor Authentication (MFA).

Contact Information

This User's contact information. Checking the Receive Notifications checkbox will include this User in the list of Users who receive email notifications when Alerts are triggered.

Settings

Module

Refresh Rate

List Views

Increasing these values will affect Vulnerability ProtectionDeep Security Manager performance.

Reports

Reset to Default Settings: Reset all settings on this page to their defaults.

Synchronizing with a Directory

The User list can be synchronized with an Active Directory, allowing Users to sign in with the password stored in the directory. Clicking Synchronize with Directory in the toolbar will display the Synchronize with Directory wizard. Type the name of the directory server and your access credentials. You will then be prompted to select which Active Directory Group of Users to import and whether they will be Users or Contacts. Once they've been imported, you are given the option to create a Scheduled Task to periodically synchronize with the directory to keep your list up to date. The imported list of Users are locked out of the Vulnerability ProtectionDeep Security Manager by default. You will have to modify their Properties to allow them to sign in to the Manager.

To successfully import an Active Directory user account into Vulnerability ProtectionDeep Security as a Vulnerability ProtectionDeep Security User or Contact, the Active Directory user account must have a userPrincipalName attribute value. (The userPrincipalName attribute corresponds to an Active Directory account holder's "User logon name".)
If you delete a User from Vulnerability ProtectionDeep Security Manager who was added as a result of synchronizing with an Active Directory and then re-synchronize with the directory, the User will reappear in your User list (if they are still in the Active Directory).

Filtering the Active Directory

The first page of the Synchronize with Directory wizard has an area called Search Options where you can write filters to specify a subset of Users to import into the Vulnerability ProtectionDeep Security Manager. The filter language follows the Internet Engineering Task Force "Lightweight Directory Access Protocol (LDAP): String Representation of Search Filters RFC 4515".

The default filter, "(objectClass=group)", imports all Users.

The RFC 4515 filter syntax can be used to filter for specific Users and/or Groups in a directory. For example, the following filter would import only Users who are members of an Active Directory group called "DeepSecurityUsers": "(&(objectClass=group)(cn=DeepSecurityUsers))".

The RFC 4515 definition is available at http://datatracker.ietf.org/doc/rfc4515/.

The new Users, although being in the "locked out" state, are given the "Full Access" User Role.