User Account

An admin account with all the privileges (Super Admin role) is created with default credentials during set up. The default admin user can add more user accounts to delegate administration and management tasks to other users.

RUCKUS Network Director allows you to create user accounts with role-based access control in RUCKUS Network Director. Role-based access control governs the permissions granted to a user by assigning specific roles to a user account. Each role has a certain degree of privileges or permissions that determine the functional access level.

RUCKUS Network Director supports the following roles:

  • Super Admin: A user who is assigned the role of super admin has complete privileges and can perform any actions on all the modules.
  • Admin: A user who is assigned the role of admin has restricted privileges and is not allowed to perform RUCKUS Network Director system-level tasks such as DB backup, upgrade, user creations and so on. The user works at the level of an operator with the privileges to configure clusters and APs.
  • View: The user assigned with the View role is limited to monitoring the system and is permitted only to view information but cannot create, modify, or delete it.

User Authentication Support Through AD and LDAP

RUCKUS Network Director supports additional user accounts that can be authenticated using external authentication server such as Lightweight Directory Access Protocol (LDAP) and Active Directory (AD). Ruckus Network Director supports authentication of three types of users classified in terms of the location where they are stored.

  • Local users: Local users are users that are created, stored, and managed on the RUCKUS Network Director's local database. Such users can access the RUCKUS Network Director application once the user login credentials are validated against the user details in the RUCKUS Network Director server.
  • AD users: Users stored in the Active Directory server.
  • LDAP users: Users stored in LDAP server.
    Note: In 2.0 release, single sign-on to SZ is not available for AD users and LDAP users.

With the addition of AD and LDAP support for user authentication, enterprise-wide authentication support is provided, irrespective of the location where the user identities are stored. To enable user authentication through AD and LDAP, the server credentials of both AD and LDAP must be configured in RUCKUS Network Director. In addition to this, you must establish a mapping between the user attributes and the user role, so that the user can be authenticated and apply the role policy.