of this group. Enter a DN from the directory (for example, CN=Group1, OU=Managed Groups,
DC=domain, DC=extension).
Shortened DNs are also supported (for example, Group1). The shortened DN is not a unique match.
Hewlett Packard Enterprise recommends using the fully qualified DN.
•
Group SID
(Security ID)—Microsoft Security ID is used for Kerberos and directory group
authorization. This value is required for Kerberos authentication. The required format is
S-1-5-2039349.
Directory group privileges
The following privileges apply to directory groups:
•
Login
— Enables directory users to log in to iLO.
•
Remote Console
—Enables directory users to access the host system Remote Console, including
video, keyboard, and mouse control.
Users with this privilege can access the BIOS, and therefore might be able to perform host-based
BIOS, iLO, storage, and network configuration tasks.
•
Virtual Power and Reset
—Enables directory users to power-cycle or reset the host system. These
activities interrupt the system availability. A user with this privilege can diagnose the system by using
the
Generate NMI to System
button.
•
Virtual Media
—Enables directory users to use the Virtual Media feature on the host system.
•
Host BIOS
—Enables directory users to configure the host BIOS settings by using the UEFI
System Utilities.
•
Configure iLO Settings
—Enables directory users to configure most iLO settings, including
security settings, and to update the iLO firmware. This privilege does not enable local user account
administration.
After iLO is configured, revoking this privilege from all users prevents reconfiguration with the iLO web
interface, iLO RESTful API, HPQLOCFG, or the CLI. Users who have access to the UEFI System
Utilities or HPONCFG can still reconfigure iLO. Only a user who has the Administer User Accounts
privilege can enable or disable this privilege.
•
Administer User Accounts
—Enables directory users to add, edit, and delete local iLO user
accounts.
•
Host NIC
—Enables directory users to configure the host NIC settings.
•
Host Storage
—Enables directory users to configure the host storage settings.
•
Recovery Set
—Enables directory users to manage the critical recovery install set.
By default, this privilege is assigned to the default Administrator account. To assign this privilege to
another account, log in with an account that already has this privilege.
This privilege is not available if you start a session when the system maintenance switch is set to
disable iLO security.
Directory group privileges
209