Users

This chapter provides the following details:

Managing Users

cnMaestro allows you to add Users using the Administration > Users page.

Note

  • cnMaestro X account supports up to 200 users.

  • cnMaestro Essentials account supports only up to 10 users.

Figure 1 Adding Users

Role-Based Access

cnMaestro supports the following user Roles:

Note

  • cnMaestro allows one to limit the number of concurrent sessions for each Role and display current active user sessions.

  • CPI role is authorized only when the CBRS is Enabled.

Role-Mappings

The table below defines how Roles are authorized to access specific features.

Table 1 Role-Mappings

Feature

Description

Access Control Policies

Configure policies to control users connectivity to the network.

  • Super Administrator - All

  • Administrator - All

  • Operator - All

  • Monitor - None

  • CPI - None

Application Operations

Application level operations such as to create, update and delete operations for Networks, Towers/Sites. Bulk device configuration.

  • Super Administrator - All

  • Administrator - All

  • Operator - None

  • Monitor - None

  • CPI - None

Application Settings

Change global application configuration and onboarding key.

  • Super Administrator - All

  • Administrator - All

  • Operator - None

  • Monitor - None

  • CPI - None

Assists

Scan device configurations and generate assists scores, which in turn helps in isolating configuration issues in a deployment.

  • Super Administrator - All

  • Administrator - All

  • Operator - All

  • Monitor - All (Fix Now is not allowed)

  • CPI - All (Fix Now is not allowed)

Citizen Broadband Radio Service Subscription (CBRS)

Support CBRS-compliant devices in the 3.6 GHz band (from 3550 MHz to 3700 MHz)

  • Super Administrator - All

  • Administrator - All

  • Operator - None

  • Monitor - None

  • CPI - All

cnArcher Installation Summary

View installation summary of PMP ePMP, and cnRanger SMs installed using the cnArcher Mobile Application.

  • Super Administrator - All

  • Administrator - All

  • Operator - All

  • Monitor - None

  • CPI - View

Configuration/Software Update

Manage configuration/software update jobs.

  • Super Administrator - All

  • Administrator - All

  • Operator - All

  • Monitor - None

  • CPI - None

Custom Applications

Configure applications with a specific IP address or a domain name, and apply filter rules.

  • Super Administrator - All

  • Administrator - All

  • Operator - All

  • Monitor - None

  • CPI - None

Device Operations

Device operations such as reboot device, link test, connectivity test, tech support file download, and Wi-Fi performance test.

  • Super Administrator - All

  • Administrator - All

  • Operator - All

  • Monitor - None

  • CPI - None

Device Overrides

Per-device configuration, including updating AP Group and applying configuration.

  • Super Administrator - All

  • Administrator - All

  • Operator - All

  • Monitor - None

  • CPI - None

EasyPass

Create captive portal using EasyPass to allow clients to access the network through Free Tiers, Vouchers, or Paid Access types.

  • Super Administrator - All

  • Administrator - All

  • Operator -View

  • Monitor - View (Sessions Only)

  • CPI - None

Floor Plan

Floor Plan configuration

  • Super Administrator - All

  • Administrator - All

  • Operator - View

  • Monitor - View

  • CPI - None

Global Configuration

The ability to create and apply configuration for global features such as Templates, WLANs, AP Groups, and bulk sync configuration.

  • Super Administrator - All

  • Administrator - All

  • Operator -View

  • Monitor - None

  • CPI - None

Guest Portal

Guest Portal configuration.

  • Super Administrator - All

  • Administrator - All

  • Operator -View

  • Monitor - View (Sessions Only)

  • CPI - None

LTE

Manage cnRanger LTE devices.

  • Super Administrator - All

  • Administrator - All

  • Operator - View and Edit SIM credentials only

  • Monitor - None

  • CPI - None

Monitoring

Display of monitoring data at all levels.

  • Super Administrator - All

  • Administrator - All

  • Operator - All

  • Monitor - View

  • CPI - View

Notifications

Alarms and Events management.

  • Super Administrator - All

  • Administrator - All

  • Operator - All

  • Monitor - View

  • CPI - View

Onboarding

Device approval, modifying individual device configuration, and performing software update.

  • Super Administrator - All

  • Administrator - All

  • Operator - All

  • Monitor - None

  • CPI - All

Reporting

Report generation.

  • Super Administrator - All

  • Administrator - All

  • Operator - All

  • Monitor - All

  • CPI - All

Session Management

Capability to view and logout other users sessions.

  • Super Administrator - All

  • Administrator - All

  • Operator - None

  • Monitor - None

  • CPI - None

Software Upgrade

Upgrade the device with the latest software.

  • Super Administrator - All

  • Administrator - All

  • Operator - All

  • Monitor - None

  • CPI - None

Spectrum Analyzer

Analyze and monitor wireless spectrum for optimizing network performance on PMP devices.

  • Super Administrator - All

  • Administrator - All

  • Operator - All

  • Monitor - None

  • CPI - None

User Management

User management operations such as manage users and roles.

  • Super Administrator - All

  • Administrator - View

  • Operator - None

  • Monitor - None

  • CPI - None

Creating Users and Configuring User Roles

To add an administrator:

  1. Navigate to Administration > Users page.

  2. Click Add User button. The following window is displayed:

  3. Enter the email address in the Email box.

  4. To configure the User Role, select any one of the role for the user from the Role drop-down list:

  5. Click Send button to add this user.

To edit or delete a user, click the Edit icon or the Delete icon against the user in the Administration > Users page.

Whitelisting specific domains

Using the Administration > Users page, you can allow (or whitelist) a specific domain (for example, gmail.com). When users from the whitelisted (or allowed) domain are added, an invite email is sent directly to them. When the users accept the invite, they are allowed to access a particular cnMaestro UI account.

You can also blacklist or disallow a specific domain to prohibit all users of that domain from accessing the UI account.

Note

  • Domain whitelisting is not applicable to NFR User accounts.

  • For users from the whitelisted domains, you can create the MSP user account.

To whitelist or blacklist a specific domain, perform the following steps:

  1. Navigate to Administration > Users page.

    The Manage Users page appears.

  2. To add a new domain (for example, a gmail ID ), click on the Add User button.

    The Add User window appears. You must set the fields, as described in the Creating Users and Configuring User Roles section. The Add User window also displays that the email ID used is a new domain, as shown in the following ex

    ample (in this case, gmail.com is the new domain):

  3. Select the Allow users in "gmail.com" domain checkbox (the domain name varies based on the email ID you add).

    The new domain is added to the database.

    When users who belong to this allowed domain (for example, gmail.com) are added (using the Add User button), an invite email is directly sent to the users. When the users accept the invite, they can access a particular cnMaestro UI account. The Allow users in "gmailail.com" domain checkbox is available only when you are adding a new domain.

  4. To blacklist or disallow a specific domain, click on the Allowed Domains button on the Manage Users page.

    The Allowed Domain window appears with a list of whitelisted domains.

  5. Clear the required domain checkbox to blacklist that specific domain.

  6. Select Update.

All users from that blacklisted domain are not allowed to access the UI. To allow the blacklisted domain, you must check the required domain checkbox on the Allowed Domain window.

Assigning roles for IdP-based domain users

A group mapping is a link between cnMaestro roles and IdP roles or groups. When signing in to cnMaestro, roles can be automatically assigned based on roles in the IdP. This can be used to maintain roles in Active Directory or a similar central identity provider.

Create a group mapping for each set of roles that you want to assign to a user based on the user’s IdP group memberships. Your organization might have groups with different sets of permissions based on teams, Cloud environments, or read/write/admin access. You can create a group mapping for each set of permissions. For example, you might create a group mapping that assigns the roles DeveloperWrite and ResourceOwner to a user who is a member of the data-science group in your IdP server.

Note

The IdP role mapping configuration is applicable only to cnMaestro X accounts.

To set up IdP role mapping, contact Cambium Support who will ask for some information and generate an IdP role mapping key.

With the IdP role mapping key, IdP groups or roles can be mapped to a role in cnMaestro for the IdP domain users. For example, with an Active Directory group called app-cnmaestro-superadmin mapped to the "Super Administrator" role in cnMaestro, members of this Active Directory group will be assigned the Super Administrator role automatically when logging in.

Advantages

The advantages of IdP-based domain user role configuration are:

Using the Administration > Users > IdP Role-Mappings UI page in cnMaestro, a new IdP role-mapping can be added and roles can be assigned to the IdP domain users.

Prerequisite tasks

Before adding IdP role-mappings and assigning roles in cnMaestro, make sure to complete the following prerequisite tasks:

Assigning roles for IdP-based domain users

To add a new role-mapping and assign a role for the IdP-based domain users, complete the following steps:

  1. Navigate to Administration > Users > IdP Role-Mappings.

  2. Click Add IdP Role Mapping.

    The Add IdP Role-Mapping box appears.

  3. In the IdP Role Mapping Key text box, enter the key provided by the Cambium Support team.

  4. Click Validate.

    On successful validation of the IdP, you can view the IdP details configured on the Support site. For example, IdP name and domain.

  5. In the Add IdP Role-Mapping box, assign the required roles to the user groups.

  6. Click Add.

    When domain users log in to the cnMaestro UI, they can access multiple accounts with a single log-in.

Session Management

View and optionally log out current cnMaestro administrator sessions. The users with Super Administrator role can logout all other users sessions and the users with Administrator roles can logout Operator and Monitor accounts.

Sessions

Displays the detailed information on the user sessions.