Access Control:
User Category Permission
Storage administrator Allowed
Storage integration administrator Disallowed
Application administrator Disallowed
Security administrator Disallowed
Read-only users Disallowed
Technicians Disallowed
Completion Codes:
v USER_GROUP_NAME_DOES_NOT_EXIST
User group name does not exist
v USER_NAME_DOES_NOT_EXIST
User name does not exist
v USER_ALREADY_INCLUDED_IN_ANOTHER_GROUP
User is included in another user group
v USER_GROUP_ALREADY_INCLUDES_USER
User group already includes user
v ONLY_APPLICATION_ADMIN_USERS_CAN_BE_GROUPED
User groups can only contain application administrators
v USER_GROUP_HAS_MAXIMUM_NUMBER_OF_USERS
User group already has the maximum number of users
v LDAP_AUTHENTICATION_IS_ACTIVE
Command is not available while LDAP authentication is active
Creating User Groups
Creates a user group.
user_group_create user_group=UserGroup
[ access_all=<yes|no> ] [ ldap_role=LdapRole ]
Parameters:
Name Type Description Mandatory Default
user_group Object name Name of the user
group to be
created.
Y N/A
access_all Boolean Allows application
administrators the
ability to perform
their specified
operations on all
volumes and not
just a subset of the
specific volumes
Nno
ldap_role String The value
representing the
user group in
LDAP.
N [none]
Chapter 18. Access Control
381