io-key
26
>
14.1.4
User administration and access control
59432
The ifm cloud uses a standard authentication and authorisation process based on realms, users, user
groups and authorities. A realm is a database of users and user groups that share the same
authentication and authorisation policy. A user is a person or external system authorised to access
protected resources within Cumulocity.
Access is controlled by means of authorisations. Authorisations define what a user may do in ifm cloud
applications. To make it easier to administer the authorisations, they are grouped in "roles".
Each user can be linked to a number of roles (e.g. administrator, read or change rights), which add up
the user's authorisations.
Each user has its own user and password administration. All logins are personalised and may only be
used by the corresponding authorised user. The user is obliged to keep the login and the password
secret and to protect them from unauthorised access by third parties.