User Management Reference

This page provides reference tables for NetXMS user management, including system access rights, object permissions, and authentication configuration variables.

For how-to guides on configuring users and authentication methods, see User Management.

System Access Rights

System access rights are global permissions that control access to server-wide functions. They can be assigned to individual users or groups.

Right Description

Access server console

Access the server debug console

Edit server configuration variables

Modify server configuration variables

View event templates configuration

View event template definitions in the event database

Configure event templates

Modify event templates in the event database

Edit event processing policy

Edit event processing policy rules

Configure SNMP traps

Create and modify SNMP trap mappings

Control user sessions

View active user sessions and force session termination

Delete alarms

Permanently delete alarms from the system

External tool integration account

Use external tool integrations

Import configuration

Import server configuration from file

Login as mobile device

Authenticate from mobile client

Configure server actions

Create and modify server actions (notifications, scripts, etc.)

Manage agent configurations

Create and modify agent configuration policies

Manage agent tunnels

Bind and unbind agent tunnels to nodes

Manage AI operators

Create and manage AI operators

Manage AI skills and functions

Create and manage AI skills

Manage AI tasks

Create and manage AI tasks

Asset management attributes

Define and modify asset management attribute schema

Manage geographical areas

Define and manage geographical areas

Manage Image Library

Upload, modify, and delete images in the image library

Manage mapping tables

Create and modify mapping tables

Manage object categories

Create and manage object categories

Manage object queries

Create and manage predefined object queries

Manage packages

Upload and manage agent upgrade packages

Manage persistent storage

Read and write persistent storage key-value pairs

Manage repositories

Manage package repositories

Manage script library

Create and modify NXSL scripts in the script library

Manage server files

Upload, download, and delete files on the server

Manage SSH keys

Manage SSH key store

Manage DCI summary tables

Create and modify DCI summary tables

Configure object tools

Create and modify object tools

Manage two-factor authentication methods

Create and configure system-wide 2FA methods

Manage users

Create, modify, and delete user accounts and groups

Manage web service definitions

Create and modify web service definitions

Read server files

Read files stored on the server

Reporting server access

Access the reporting server

Schedule file upload

Schedule file delivery tasks to managed nodes

Schedule object maintenance

Schedule maintenance windows for objects

Schedule script execution

Schedule server-side NXSL script execution

Manage all scheduled tasks

View and manage all scheduled tasks including those created by other users

Manage user scheduled tasks

View and manage scheduled tasks of all users (excluding system tasks)

Manage own scheduled tasks

Create and manage own scheduled tasks

Scan network range

Perform active scans of network address ranges

Search network

Perform ad-hoc network address searches

Send notifications

Send notifications through configured notification channels

Initiate TCP proxy sessions

Establish TCP proxy sessions through agents

Unlink helpdesk tickets

Unlink alarms from external helpdesk tickets

Use AI assistant

Interact with the AI assistant

Manage user support application notifications

Send notifications to user agents (desktop tray agents)

View action execution log

View the server action execution log

View all alarm categories

View alarms in all alarm categories regardless of alarm category access lists

View asset change log

View asset management change history

View audit log

View the server audit log

View event log

View the event log

View notification log

View the notification delivery log

View repositories

View package repository contents

View syslog

View syslog messages collected by the server

View SNMP trap log

View received SNMP trap log

View welcome page

Access the server welcome/information page

Three of these rights — Delete alarms, Manage repositories, and View repositories — are enforced by the server but not exposed on the management client’s System Rights property page, so they cannot be granted from the UI.

Object Access Control

In addition to system-wide rights, each object (node, container, etc.) has its own access control list (ACL) that determines which users can perform specific operations.

Permission Description

Read

View object and its data

Delegated read

Read the object indirectly through another object (for example, a dashboard or network map element)

Read agent data

Read DCI data collected from agent

Read SNMP data

Read DCI data collected via SNMP

Read credentials

View authentication credentials configured for the object

Read device configuration

View device configuration retrieved from the node

Modify

Change object configuration

Edit comments

Edit object comments

Manage responsible users

Modify the list of responsible users for the object

Access control

View and modify the object’s access control list

Create child objects

Create child objects

Delete

Delete the object

Control

Execute actions and object tools

Configure agent

Change configuration of the agent running on the node

Upload device configuration

Upload configuration to the device

Control maintenance mode

Enter and leave maintenance mode for the object

Edit maintenance journal

Add and modify entries in the object’s maintenance journal

Manage policies

Manage agent policies (template objects)

Send events

Send events on behalf of the object

Push data

Push DCI data for the object

View alarms

View alarms related to the object

Update alarms

Acknowledge and resolve alarms related to the object (terminating requires the separate Terminate alarms right)

Terminate alarms

Terminate alarms related to the object

Create helpdesk tickets

Create helpdesk tickets for alarms

Manage incidents

Create and manage incidents for the object

Download files

Download files from the managed node

Upload files

Upload files to the managed node

Manage files

Manage files on the managed node (rename, delete)

Query web service

Execute web service requests through the object

Take screenshot

Capture screenshots (for Windows agent)

Access rights are inherited from parent objects only when the object’s inherit access rights flag is set. Even then, the parent objects' ACLs are consulted only if the user has no direct ACL entry on the object itself — a direct entry fully replaces inherited rights. If an object has multiple parents, rights inherited from them are combined (OR-ed).

Account Lockout Variables

Variable Default Description

Server.Security.IntruderLockoutThreshold

0

Failed login attempts before lockout (0=disabled)

Server.Security.IntruderLockoutTime

30

Lockout duration in minutes

Password Policy Variables

Variable Default Description

Server.Security.MinPasswordLength

0

Minimum password length (0=no minimum); applies only when no per-user minimum password length is set in the user’s properties

Server.Security.PasswordComplexity

0

Required password complexity as a bitmask (see below)

Server.Security.PasswordExpiration

0

Password expiration time in days (0=never expires)

Server.Security.PasswordHistoryLength

0

Number of previous passwords to keep; users cannot reuse any password in the history

The PasswordComplexity value is a bitmask constructed by adding the following flags:

Flag Requirement

1

Password must contain at least one digit (0-9)

2

Password must contain at least one uppercase letter (A-Z)

4

Password must contain at least one lowercase letter (a-z)

8

Password must contain at least one special character (e.g., ~!@#$%^&*()_-=+)

16

Forbid alphabetical sequences (3 or more consecutive letters in the same case, e.g., "abc")

32

Forbid keyboard sequences (3 or more characters adjacent on the keyboard, e.g., "qwe" or "!@#")

For example, to require digits, uppercase letters, and special characters, set PasswordComplexity to 1 + 2 + 8 = 11.

MinPasswordLength, PasswordComplexity, and PasswordHistoryLength are enforced only when users change their own password. An administrator setting another user’s password bypasses all password policy checks.

LDAP Configuration Variables

Variable Default Description

LDAP.ConnectionString

ldap://localhost:389

LDAP server URI; use ldap:// for unencrypted connections or ldaps:// for TLS

LDAP.SyncUser

(empty)

DN or UPN of the service account for LDAP queries

LDAP.SyncUserPassword

(empty)

Password for the sync account

LDAP.SearchBase

(empty)

Base DN for user/group search (e.g., DC=example,DC=com)

LDAP.SearchFilter

(empty)

LDAP search filter string applied when querying for users and groups

LDAP.SyncInterval

0

Sync interval in minutes (0=manual sync only)

LDAP.UserClass

(empty)

LDAP object class for users

LDAP.GroupClass

(empty)

LDAP object class for groups

LDAP.Mapping.UserName

(empty)

LDAP attribute mapped to NetXMS login name

LDAP.Mapping.FullName

displayName

LDAP attribute mapped to display name

LDAP.Mapping.Description

(empty)

LDAP attribute mapped to description

LDAP.Mapping.Email

(empty)

LDAP attribute mapped to email address

LDAP.Mapping.PhoneNumber

(empty)

LDAP attribute mapped to phone number

LDAP.Mapping.GroupName

(empty)

LDAP attribute mapped to NetXMS group name

LDAP.UserUniqueId

(empty)

LDAP attribute used as unique identifier for users (default: DN); recommended: objectGUID for AD, entryUUID for OpenLDAP

LDAP.GroupUniqueId

(empty)

LDAP attribute used as unique identifier for groups (default: DN); recommended: objectGUID for AD, entryUUID for OpenLDAP

LDAP.UserDeleteAction

1

Action when LDAP user is deleted: 0=delete from NetXMS, 1=disable in NetXMS

LDAP.NewUserAuthMethod

5

Authentication method assigned to newly created LDAP users (5 = LDAP password)

LDAP.PageSize

1000

Number of records per LDAP search page (for paged result control)

Setting LDAP.UserUniqueId and LDAP.GroupUniqueId is recommended. Without it, the DN is used as the unique identifier, and moving a user or group to a different OU in the LDAP directory will cause NetXMS to treat it as a deletion and re-creation.

RADIUS Configuration Variables

Variable Default Description

RADIUS.Server

none

Hostname or IP address of primary RADIUS server; the literal value none means not configured

RADIUS.Secret

netxms

Shared secret for primary RADIUS server

RADIUS.Port

1645

Authentication port for primary RADIUS server

RADIUS.SecondaryServer

none

Hostname or IP address of secondary (failover) RADIUS server; the literal value none means not configured

RADIUS.SecondarySecret

netxms

Shared secret for secondary RADIUS server

RADIUS.SecondaryPort

1645

Authentication port for secondary RADIUS server

RADIUS.AuthMethod

PAP

Authentication method: PAP, CHAP, MS-CHAPv1, or MS-CHAPv2

RADIUS.NumRetries

5

Number of retries on timeout

RADIUS.Timeout

3

Response timeout in seconds

RADIUS.NASIdentifier

(empty)

Value for the NAS-Identifier attribute in RADIUS requests; if empty, the attribute is not sent

RADIUS.ServiceType

8

Value for the Service-Type attribute in RADIUS requests (0=do not include attribute)

Two-Factor Authentication Variables

Variable Default Description

Server.Security.2FA.EnforceForAll

false

Enforce two-factor authentication for every user regardless of group membership (individual users can still be exempted via the account flag). Checked before the per-group enforcement flags.

Server.Security.2FA.TrustedDeviceTTL

0

Time-to-live for trusted device tokens (seconds; 0 = require 2FA every login)

Server.Security.2FA.TokenTimeout

120

Time in seconds the user has to respond to a 2FA challenge before the client cancels the prompt; 0 disables the auto-cancel timer. The server itself does not expire the challenge.

Server.Security.2FA.GraceLoginCount

5

Grace logins allowed when 2FA is enforced for a user but no 2FA method is configured at all; after they are used up, 2FA setup becomes mandatory. Read as the fallback default for a per-user counter.

CAS Configuration Variables

Variable Default Description

CAS.Host

localhost

CAS server hostname

CAS.Port

8443

CAS server port

CAS.ValidateURL

/cas/serviceValidate

URL path for CAS ticket validation

CAS.Service

https://127.0.0.1/nxmc

Service identifier sent to CAS server during validation

CAS.TrustedCACert

(empty)

Path to CA certificate file for validating the CAS server’s SSL certificate

CAS.AllowedProxies

(empty)

Comma-separated list of allowed CAS proxy server addresses; required if using proxy authentication

Configuration changes take effect immediately without a server restart. The CAS server validates both service tickets (ST-) and proxy tickets (PT-). The validated user principal name is matched against NetXMS user login names.

Certificate Mapping Methods

Each user configured for certificate authentication must have a mapping method and mapping data set in their user properties.

Method Description

Subject

The full certificate subject (Distinguished Name) must match the mapping data (case-insensitive comparison)

Public Key

The certificate’s public key must match the mapping data (hex-encoded public key data)

Common Name

The Common Name (CN) field of the certificate subject must match the mapping data; if mapping data is empty, the CN is compared against the user’s login name

Template ID

The certificate template ID (Microsoft AD CS) must match the mapping data

The management client offers only Subject, Public key, and Common name; the Template ID method is supported by the server but cannot be selected from the UI.

UI Access Rule Evaluation

Access rules are stored as a semicolon-separated list and are case-insensitive (lowercased before matching). Each rule has the form type:id, optionally preceded by a prefix (see below), where type is p (or perspective), v (or view), or . A rule without a colon is silently ignored. or : matches all UI elements, and the id part supports * and ? wildcards.

Rules are evaluated in order of priority using prefixes:

Prefix Type Description

^

Priority inclusion

Highest priority; if matched, the element is always visible regardless of other rules

!

Exclusion

If matched, the element is hidden

(none)

Inclusion

If matched, the element is visible

When determining whether a UI element is visible for a user, all rules from the user account and all groups the user belongs to are combined, then evaluated — rules for the element’s specific category (p: or v:) are consulted before *-category rules at each priority level:

  1. Priority inclusions for the element’s category — if any match, the element is visible

  2. Exclusions for the element’s category — if any match, the element is hidden

  3. Priority inclusions in the * category — if any match, the element is visible

  4. Exclusions in the * category — if any match, the element is hidden

  5. A match-all inclusion ( or :*) makes the element visible

  6. Inclusions for the element’s category — if any match, the element is visible

  7. Inclusions in the * category — if any match, the element is visible

  8. If no rules matched, the element is hidden

Note the consequence of this ordering: a category-specific exclusion (!v:foo) overrides a wildcard-category priority inclusion (^*:foo).

Audit Log Variables

Variable Default Description

AuditLog.External.Server

none

External syslog server hostname or IP address; the literal value none disables external audit logging

AuditLog.External.Port

514

UDP port for external syslog server

AuditLog.External.Facility

13

Syslog facility code for audit messages

AuditLog.External.Severity

5

Syslog severity level for audit messages

AuditLog.External.Tag

netxmsd-audit

Syslog tag prefix for audit messages

AuditLog.External.UseUTF8

false

Send audit messages to the external syslog server in UTF-8 encoding

AuditLog.RetentionTime

90

Number of days to retain internal audit records (purged by housekeeper)

Changes to AuditLog.External.* variables take effect only after a server restart, except AuditLog.External.UseUTF8, which is applied immediately.