Changes for page Benutzerverwaltung

Last modified by Sabrina V. on 2026/08/10 08:17

From version 5.1
edited by Sabrina V.
on 2026/08/10 08:17
Change comment: There is no comment for this version
To version 2.1
edited by Sabrina V.
on 2026/07/23 08:41
Change comment: There is no comment for this version

Summary

Details

Page properties
Content
... ... @@ -9,7 +9,7 @@
9 9  
10 10  |=(% style="width: 437px;" %)Components of Rights Management|=(% style="width: 1035px;" %)Description
11 11  |(% style="width:437px" %)Fundamental Rights|(% style="width:1035px" %)(((
12 -Basic rights refer to the rights that are assigned to users and groups directly during creation or in user management and that apply across the entire ACMP Console. Using these rights, you can, for example, specify which ACMP Solutions a user is allowed to view and which actions they are permitted to perform within a solution. For more info, you can jump to the section on [[Rights of User>>doc:||anchor="HManagingUsersandGroupsinACMP"]].
12 +Basic rights refer to the rights that are assigned to users and groups directly during creation or in user management and that apply across the entire ACMP Console. Using these rights, you can, for example, specify which ACMP Solutions a user is allowed to view and which actions they are permitted to perform within a solution. For more info, you can jump to the section on [[Rights of User>>doc:||anchor="HRechtedesBenutzersfestlegen"]].
13 13  )))
14 14  |(% style="width:437px" %)Component-Specific Permissions|(% style="width:1035px" %)Component-specific permissions allow you to specify, for individual system components and elements - such as reports, Client Commands, or folders - which users are allowed to view and, if applicable, edit each component. These permissions are managed through individual access lists for each component. For more information on permissions, see the “Access Lists” section.
15 15  
... ... @@ -17,13 +17,13 @@
17 17  
18 18  Closely linked to the basic rights and specific permissions are the default user //ADMINISTRATOR// and the default group //Privileged users//. The //ADMINISTRATOR// user account has all existing rights and permissions in the ACMP Console and cannot be edited or deleted. The “Privileged users” group, on the other hand, is a default group that cannot be edited through general user management. This group is created dynamically and individually for each access list in ACMP. This means that this group includes all users who have the basic right to view the respective solution containing the specific access list. Thus, the //Privileged users// group can be used to control which individual components users within a specific solution can view and use. For more information on working with access lists, see the section “Access Lists in ACMP.”
19 19  
20 -= Managing Users and Groups in acmp =
20 += Managing Users and Groups in ACMP =
21 21  
22 22  In the overview, you'll see the two tabs, “Users” and “Groups,” under which the respective items are displayed. When you first open the view, the focus is on the users.
23 23  
24 24  [[User Management>>image:68_System_Benutzerverwaltung Übersicht_1821.png||alt="63_System_Benutzerverwaltung_1696.png" data-xwiki-image-style-alignment="center"]]
25 25  
26 -Depending on which option you selected ([[Users>>doc:||anchor="HManageUsers"]] or [[Groups>>doc:||anchor="HManageGroups"]]), the commands in the ribbon bar will change. However, you can [[import AD users>>doc:||anchor="HImportActiveDirectoryUsers"]] from either tab at any time. In the left pane, you’ll see a list of all created users, from which you can, for example, see at a glance what roles they have been assigned and whether multi-factor authentification (MFA) is activated. On the right side is the detail view for the currently selected user.
26 +Depending on which option you selected ([[Users>>doc:||anchor="HBenutzerverwalten"]] or [[Groups>>doc:||anchor="HGruppenverwalten"]]), the commands in the ribbon bar will change. However, you can [[import AD users>>doc:||anchor="HActiveDirectory-Benutzerimportieren"]] from either tab at any time. In the left pane, you’ll see a list of all created users, from which you can, for example, see at a glance what roles they have been assigned and whether multi-factor authentification (MFA) is activated. On the right side is the detail view for the currently selected user.
27 27  
28 28  Legend
29 29  
... ... @@ -90,7 +90,7 @@
90 90  
91 91  **Assign Groups**
92 92  
93 -In the second step, specify the group membership. In most cases, [[groups>>doc:||anchor="HManageGroups"]] have different rights. A user can be assigned to multiple groups. There is no requirement to assign a user to a group. Some groups are already provided when you install ACMP (including //AD Login//, //Full access//, and //Secured by MFA//).
93 +In the second step, specify the group membership. In most cases, [[groups>>doc:||anchor="#Gruppen"]] have different rights. A user can be assigned to multiple groups. There is no requirement to assign a user to a group. Some groups are already provided when you install ACMP (including //AD Login//, //Full access//, and //Secured by MFA//).
94 94  
95 95  {{aagon.warnungsbox}}
96 96  For security reasons, it is not recommended to assign a user to multiple groups. Instead, you can, for example, create a separate group for the user.
... ... @@ -111,7 +111,7 @@
111 111  
112 112  **Select Roles and Tenants**
113 113  
114 -Now define roles and tenants for the user. You can specify whether the user should be assigned a Helpdesk role, which would allow them to become a ticket editor. You can also specify whether the user can view and manage all tenants, only selected tenants, or none at all. If you want to use [[multi tenancy>>doc:ACMP.610.Mandantenfähigkeit in ACMP.WebHome]] in ACMP, you must grant the user access to all tenants or at least selected tenants.
114 +Now define roles and tenants for the user. You can specify whether the user should be assigned a Helpdesk role, which would allow them to become a ticket editor. You can also specify whether the user can view and manage all tenants, only selected tenants, or none at all. If you want to use [[multi tenancy>>doc:ACMP.610.ACMP-Solutions.System.Einstellungen.ACMP Server.WebHome||anchor="HMandantenfE4higkeit"]] in ACMP, you must grant the user access to all tenants or at least selected tenants.
115 115  
116 116  (% class="box warningmessage" %)
117 117  (((
... ... @@ -123,6 +123,7 @@
123 123  [[Define Roles and Tenants>>image:Benutzerverwaltung_Rollen und Mandanten.png]]
124 124  
125 125  
126 +
126 126  **Set ACMP Contact**
127 127  
128 128  In the final step, you can assign an existing contact from the Helpdesk to the user or create a new contact for the user
... ... @@ -153,6 +153,8 @@
153 153  
154 154  [[Group Overview in User Management>>image:68_Benutzerverwaltung_Gruppen Übersicht_1660.png||alt="67_Benutzerverwaltung_Gruppen Übersicht_1660.png"]]
155 155  
157 +
158 +
156 156  === **Add Group** ===
157 157  
158 158  Click the //Add// button on the ribbon bar to create a new group. In the wizard that opens, first enter a name and, optionally, a description for the group.
... ... @@ -175,9 +175,10 @@
175 175  
176 176  **Select Roles and Tenants**
177 177  
178 -Now define the roles and tenants for the group. You can specify whether members of this group should be assigned a Helpdesk role, which would allow them to become ticket editors. A member of this group can thus act as a Helpdesk agent to create, edit, and process tickets. You can also specify whether members of this group can view and manage all tenants, only selected tenants, or none at all. If you want to use [[multi tenancy>>doc:ACMP.610.Mandantenfähigkeit in ACMP.WebHome]] in ACMP, you must grant the user access to all tenants or at least selected tenants.
181 +Now define the roles and tenants for the group. You can specify whether members of this group should be assigned a Helpdesk role, which would allow them to become ticket editors. A member of this group can thus act as a Helpdesk agent to create, edit, and process tickets. You can also specify whether members of this group can view and manage all tenants, only selected tenants, or none at all. If you want to use [[multi tenancy>>doc:ACMP.610.ACMP-Solutions.System.Einstellungen.ACMP Server.WebHome||anchor="HMandantenfE4higkeit"]] in ACMP, you must grant the user access to all tenants or at least selected tenants.
179 179  
180 180  
184 +
181 181  **Active Directory Group Mapping**
182 182  
183 183  This step is used to map users in an Active Directory group to the ACMP group you are currently creating. This allows you to manage users exclusively through AD, rather than having to manually create all users in ACMP again. To use this function effectively, you must specify a login group in the platform configuration that includes all users authorized to access the ACMP (see [[Login>>doc:ACMP.610.ACMP-Solutions.System.Einstellungen.ACMP Server.WebHome||anchor="HActiveDirectoryLogin"]]).
... ... @@ -257,7 +257,7 @@
257 257  
258 258  = Import Active Directory Users =
259 259  
260 -In ACMP, one or more AD groups can be assigned to a group, linked by “or.” A mapping is displayed by a corresponding icon. All members of these groups can log in to the ACMP Console and have the rights assigned to their group. A prerequisite for this is that they are also members of the respective access group specified under [[AD Login>>doc:ACMP.610.ACMP-Solutions.System.Einstellungen.ACMP Server.WebHome||anchor="HActiveDirectoryLogin"]]. Manually adding users is not necessary in this case, but it remains possible, allowing users to be managed entirely within Active Directory.
264 +In ACMP, one or more AD groups can be assigned to a group, linked by “or.” A mapping is displayed by a corresponding icon. All members of these groups can log in to the ACMP Console and have the rights assigned to their group. A prerequisite for this is that they are also members of the respective access group specified under [[AD Login>>doc:||anchor="HActiveDirectory-Anmeldung"]]. Manually adding users is not necessary in this case, but it remains possible, allowing users to be managed entirely within Active Directory.
261 261  
262 262  If a user logs in this way, the system automatically adds them to the ACMP Database. Alternatively, all users can be manually imported into the database using the //Import all new AD users from the AD access group into the database// function. This does not involve user synchronization, so existing users are neither imported into AD nor deleted from it. Users who have been deleted from Active Directory or removed from a group are not deleted from the ACMP Database, but are merely removed from the corresponding ACMP groups.
263 263  
© Aagon GmbH 2026
Besuchen Sie unsere aagon-Community