NetBackup™ Web UI Administrator's Guide
- Section I. About NetBackup
- Section II. Monitoring and notifications
- Monitoring NetBackup activity
- Activity monitor
- Job monitoring
- Troubleshooting the viewing and managing of jobs
- Device monitor
- Notifications
- Registering the data collector
- Monitoring NetBackup activity
- Section III. Configuring hosts
- Managing host properties
- Busy file settings properties
- Client attributes properties
- Client settings properties for UNIX clients
- Client settings properties for Windows clients
- Data Classification properties
- Default job priorities properties
- Encryption properties
- Exchange properties
- Exclude list properties
- Fibre transport properties
- General server properties
- Global attributes properties
- Logging properties
- Media properties
- Network settings properties
- Port ranges properties
- Preferred network properties
- Resilient network properties
- Restore failover properties
- Retention periods properties
- Scalable Storage properties
- Servers properties
- SharePoint properties
- SLP settings properties
- Managing credentials for workloads and systems that NetBackup accesses
- Managing deployment
- Managing host properties
- Section IV. Configuring storage
- Overview of storage options
- Configuring disk storage
- Integrating MSDP Cloud and CMS
- Create a universal share
- Managing media servers
- Configuring storage units
- Managing tape drives
- Managing robots and tape drives
- Inventorying robots
- Managing volumes
- Managing volume pools
- Managing volume groups
- Staging backups
- Troubleshooting storage configuration
- Section V. Configuring backups
- Overview of backups in the NetBackup web UI
- Managing protection plans
- Managing classic policies
- Protecting the NetBackup catalog
- Catalog backups
- Managing backup images
- Pausing data protection activity
- Section VI. Managing security
- Security events and audit logs
- Managing security certificates
- Managing host mappings
- Configuring multi-person authorization
- Managing user sessions
- Configuring multifactor authentication
- Managing the global security settings for the primary server
- About trusted primary servers
- Using access keys, API keys, and access codes
- Configuring authentication options
- Managing role-based access control
- Disabling access to NetBackup interfaces for OS Administrators
- Section VII. Detection and reporting
- Detecting anomalies
- About backup anomaly detection
- Malware scanning
- Usage reporting and capacity licensing
- Detecting anomalies
- Section VIII. NetBackup workloads and NetBackup Flex Scale
- Section IX. Administering NetBackup
- Management topics
- Managing client backups and restores
- About client-redirected restores
- Section X. Disaster recovery and troubleshooting
- Section XI. Other topics
- Additional NetBackup catalog information
- About the NetBackup database
- About the NetBackup database installation
- Post-installation tasks
- Using the NetBackup Database Administration utility on Windows
- Using the NetBackup Database Administration utility on UNIX
Default RBAC roles
The NetBackup web UI provides the following default RBAC roles with preconfigured permissions and settings.
Table: Default RBAC roles in the NetBackup web UI
Role name | Description |
---|---|
Administrator | The Administrator role has full permissions for NetBackup and can manage all aspects of NetBackup. |
Default Apache Cassandra Administrator | This role has all the permissions that are necessary to manage and protect Apache Cassandra assets with protection plans. |
Default AHV Administrator | This role has all the permissions that are necessary to manage Nutanix Acropolis Hypervisor and to back up those assets with protection plans. |
Default Cloud Administrator | This role has all the permissions that are necessary to manage cloud assets and to back up those assets with protection plans. Note that a PaaS administrator requires some additional permissions that you can add to a custom role. Cloud administrators also need additional permissions to manage cloud and PaaS assets using intelligent groups. |
Default Cloud Object Store Administrator | This role has all the permissions to manage the protection for cloud objects using classic policies. |
Default IRE SLP Administrator | Manages IRE (Isolated Recovery Environment) SLP (Storage lifecycle policies) functionalities. |
Default Kubernetes Administrator | This role has all the permissions that are necessary to manage Kubernetes and to back up those assets with protection plans. The permissions for this role give a user the ability to view and manage jobs for Kubernetes assets. To view all jobs for this asset type, a user must have the default role for that workload. Or, a similar custom role must have the following option applied when the role is created: . |
Default Microsoft Sentinel Administrator | This role has all the permissions necessary to add Microsoft Sentinel credentials in NetBackup and to send NetBackup audit events to Microsoft Sentinel. |
Default Microsoft SQL Server Administrator | This role has all the permissions that are necessary to manage SQL Server databases and to back up those assets with protection plans. In addition to this role, the NetBackup user must meet the following requirements:
|
Default Multi-Person Authorization (MPA) Approver | This role has permissions to manage MPA tickets. |
Default MySQL Administrator | This role has all the permissions that are necessary to manage MySQL instances and databases and to back up those assets with protection plans. |
Default NAS Administrator | This role has all the permissions that are necessary to perform the backup and restore of NAS volumes using a policy. To view all jobs for the backups and restores of a NAS volume, a user must have this role. Or, the user must have a custom role with same permissions applied when the role was created. |
Default NetBackup Command Line (CLI) Administrator | This role has all the permissions that are necessary to manage NetBackup using the NetBackup command line (CLI). With this role a user can run most of the NetBackup commands with a non-root account. A user that has only this role cannot sign into the web UI. |
Default Oracle Administrator | This role has all the permissions that are necessary to manage Oracle databases and to back up those assets with protection plans. |
Default PostgreSQL Administrator | This role has all the permissions that are necessary to manage PostgreSQL instances and databases and to back up those assets with protection plans. |
Default Resiliency Administrator | This role has all the permissions to protect the Veritas Resiliency Platform (VRP) for VMware assets. |
Default RHV Administrator | This role has all the permissions that are necessary to manage Red Hat Virtualization computers and to back up those assets with protection plans. This role gives a user the ability to view and manage jobs for RHV assets. To view all jobs for RHV assets, a user must have this role. Or, the user must have a similar custom role with following option applied when the role was created: . |
Default SaaS Administrator | This role has all the permissions to view and manage SaaS assets. |
Default Security Administrator | This role has permissions to manage NetBackup security including role-based access control (RBAC), certificates, hosts, identity providers and domains, global security settings, and other permissions. This role can also view settings and assets in most areas of NetBackup: workloads, storage, licensing, and other areas. |
Default Storage Administrator | This role has permissions to configure disk-based storage and storage lifecycle policies. SLP settings are managed with the Administrator role. |
Default Universal Share Administrator | This role has the permissions to manage policies and storage servers. It can also manage the assets for Windows and Standard client types and for universal shares. |
Default Veritas Alta View Administrator | This role has all the permissions that are necessary to manage Veritas Alta View functionalities. |
Default VMware Administrator | This role has all the permissions that are necessary to manage VMware virtual machines and to back up those assets with protection plans. To view all jobs for VMware assets, a user must have this role. Or, the user must have a similar custom role with following option applied when the role was created: . |
NetBackup Read-Only Operator | Provides read-only permissions to the IT Analytics Operator, Multi-Person Authorization Approver, and other operators in NetBackup, with no permissions for security. |
Note:
Veritas reserves the right to update the RBAC permissions for default roles in future releases. Any revised permissions are automatically applied to users of these roles when NetBackup is upgraded. If you have copies of default roles these roles are not updated automatically. (Or, if you have any custom roles that are based on default roles.) If you want these custom roles to include changes to default roles, you must manually apply the changes or recreate the custom roles.