User Account

An admin account with all the privileges (Super Admin role) is created with default credentials during set up. The default admin user can add more user accounts to delegate administration and management tasks to other users.

RUCKUS Network Director allows you to create user accounts with role-based access control in RUCKUS Network Director. Role-based access control governs the permissions granted to a user by assigning specific roles to a user account. Each role has a certain degree of privileges or permissions that determine the functional access level.

RUCKUS Network Director supports the following roles:

  • Super Admin: A user who is assigned the role of super admin has complete privileges and can perform any actions on all the modules.
  • Admin: A user who is assigned the role of admin has restricted privileges and is not allowed to perform RUCKUS Network Director system-level tasks such as DB backup, upgrade, user creations and so on. The user works at the level of an operator with the privileges to configure clusters and APs.
  • View: The user assigned with the View role is limited to monitoring the system and is permitted only to view information but cannot create, modify, or delete it.

User Authentication Support Through AD, LDAP, and TACACS+

RUCKUS Network Director supports user authentication through external authentication servers, including Active Directory (AD), Lightweight Directory Access Protocol (LDAP), and Terminal Access Controller Access-Control System Plus (TACACS+). This enables enterprise-wide authentication across different storage locations for user identities, with authentication processed in the following order of priority: local database, AD, LDAP, and TACACS+.

RUCKUS Network Director categorizes users based on where their accounts are stored:

  • Local users: Created, stored, and managed in the RUCKUS Network Director's local database. Local users can access the RUCKUS Network Director application once the user login credentials are validated against the user details in the RUCKUS Network Director server.
  • AD users: Stored in the Active Directory server.
  • LDAP users: Stored in LDAP server.
  • TACACS+ users: Stored in TACACS+ server.
Note: Single sign-on to SZ is not available for AD, LDAP, or TACACS+ users.

To enable user authentication through AD, LDAP, or TACACS+, the server credentials are configured in RUCKUS Network Director for each service. A user-to-role mapping is also defined to ensure that role policies are correctly applied upon authentication.