Dom Prevost 0 Posted November 12, 2018 Share Posted November 12, 2018 Hi Community, is there a scenario to create a parent/child architecture to allow a group of users to access only a set of machines, task, policies, etc without disturb the "master" server. I would like to be able to manage this server from the "parent" server. The reason is because we don't want these users to see/execute the tasks that are present on the "parent" server. thank you and excuse me for my english, I'm better in french Link to comment Share on other sites More sharing options...
ESET Staff MichalJ 434 Posted November 13, 2018 ESET Staff Share Posted November 13, 2018 Hello @Dom Prevost In V6 architecture, you are able to have the usecase achieved just with one single server. We have actually lot of companies / MSPs doing it in a way, that they do give "access rights" for specific sub-admins only to a sub-portion of a tree. You can do it by creating a new native user, with a home group set to "group with the set of machines you want them to manage". Then you create a permission set, which will have write permissions to the tasks / actions mapped to the "group with the set of machine you want them to manage". In order to let them use pre-defined notifications / reports / dashboards, you can either give them read only access to the group where those objects are located (by default group All, but in this case you risk they will see also other computers). You can create a group "Shared", move the accessible objects (reports / tasks / ...) there, and then give him read only access to this group. I will instruct documentation team, to create a KB article, covering this use-case. Link to comment Share on other sites More sharing options...
ESET Staff Peter_J 3 Posted November 13, 2018 ESET Staff Share Posted November 13, 2018 Hello @Dom Prevost, you can find useful information in the Knowledgebase article on how to create a branch office structure in ERA/ESMC: https://support.eset.com/kb6321/ (ERA 6.5) https://support.eset.com/KB6881/ (ESMC 7) Link to comment Share on other sites More sharing options...
Dom Prevost 0 Posted November 16, 2018 Author Share Posted November 16, 2018 @Peter_J Thank you for the precious informations. I'm now able to add a couple of clients under our main console. 2000 agents more I found that we cannot "share" only a part of our licence. in this scenario they will need to have their own licence at their level, right? Link to comment Share on other sites More sharing options...
ESET Staff MichalJ 434 Posted November 16, 2018 ESET Staff Share Posted November 16, 2018 @Dom Prevost As of now yes. We are working on an improvement of this behavior, where you will be able to divide license into pools and give access to individuals per each pool. As of now, you have to use either one big license or smaller ones. Link to comment Share on other sites More sharing options...
Dom Prevost 0 Posted November 16, 2018 Author Share Posted November 16, 2018 @MichalJ thak you for your answer! Link to comment Share on other sites More sharing options...
Recommended Posts