User Management Reference
This page provides reference tables for NetXMS user management, including system access rights, object permissions, and authentication configuration variables.
For how-to guides on configuring users and authentication methods, see User Management.
System Access Rights
System access rights are global permissions that control access to server-wide functions. They can be assigned to individual users or groups.
| Right | Description |
|---|---|
Access server console |
Access the server debug console |
Edit server configuration variables |
Modify server configuration variables |
View event templates configuration |
View event template definitions in the event database |
Configure event templates |
Modify event templates in the event database |
Edit event processing policy |
Edit event processing policy rules |
Configure SNMP traps |
Create and modify SNMP trap mappings |
Control user sessions |
View active user sessions and force session termination |
Delete alarms |
Permanently delete alarms from the system |
External tool integration account |
Use external tool integrations |
Import configuration |
Import server configuration from file |
Login as mobile device |
Authenticate from mobile client |
Configure server actions |
Create and modify server actions (notifications, scripts, etc.) |
Manage agent configurations |
Create and modify agent configuration policies |
Manage agent tunnels |
Bind and unbind agent tunnels to nodes |
Manage AI operators |
Create and manage AI operators |
Manage AI skills and functions |
Create and manage AI skills |
Manage AI tasks |
Create and manage AI tasks |
Asset management attributes |
Define and modify asset management attribute schema |
Manage geographical areas |
Define and manage geographical areas |
Manage Image Library |
Upload, modify, and delete images in the image library |
Manage mapping tables |
Create and modify mapping tables |
Manage object categories |
Create and manage object categories |
Manage object queries |
Create and manage predefined object queries |
Manage packages |
Upload and manage agent upgrade packages |
Manage persistent storage |
Read and write persistent storage key-value pairs |
Manage repositories |
Manage package repositories |
Manage script library |
Create and modify NXSL scripts in the script library |
Manage server files |
Upload, download, and delete files on the server |
Manage SSH keys |
Manage SSH key store |
Manage DCI summary tables |
Create and modify DCI summary tables |
Configure object tools |
Create and modify object tools |
Manage two-factor authentication methods |
Create and configure system-wide 2FA methods |
Manage users |
Create, modify, and delete user accounts and groups |
Manage web service definitions |
Create and modify web service definitions |
Read server files |
Read files stored on the server |
Reporting server access |
Access the reporting server |
Schedule file upload |
Schedule file delivery tasks to managed nodes |
Schedule object maintenance |
Schedule maintenance windows for objects |
Schedule script execution |
Schedule server-side NXSL script execution |
Manage all scheduled tasks |
View and manage all scheduled tasks including those created by other users |
Manage user scheduled tasks |
View and manage scheduled tasks of all users (excluding system tasks) |
Manage own scheduled tasks |
Create and manage own scheduled tasks |
Scan network range |
Perform active scans of network address ranges |
Search network |
Perform ad-hoc network address searches |
Send notifications |
Send notifications through configured notification channels |
Initiate TCP proxy sessions |
Establish TCP proxy sessions through agents |
Unlink helpdesk tickets |
Unlink alarms from external helpdesk tickets |
Use AI assistant |
Interact with the AI assistant |
Manage user support application notifications |
Send notifications to user agents (desktop tray agents) |
View action execution log |
View the server action execution log |
View all alarm categories |
View alarms in all alarm categories regardless of alarm category access lists |
View asset change log |
View asset management change history |
View audit log |
View the server audit log |
View event log |
View the event log |
View notification log |
View the notification delivery log |
View repositories |
View package repository contents |
View syslog |
View syslog messages collected by the server |
View SNMP trap log |
View received SNMP trap log |
View welcome page |
Access the server welcome/information page |
| Three of these rights — Delete alarms, Manage repositories, and View repositories — are enforced by the server but not exposed on the management client’s System Rights property page, so they cannot be granted from the UI. |
Object Access Control
In addition to system-wide rights, each object (node, container, etc.) has its own access control list (ACL) that determines which users can perform specific operations.
| Permission | Description |
|---|---|
Read |
View object and its data |
Delegated read |
Read the object indirectly through another object (for example, a dashboard or network map element) |
Read agent data |
Read DCI data collected from agent |
Read SNMP data |
Read DCI data collected via SNMP |
Read credentials |
View authentication credentials configured for the object |
Read device configuration |
View device configuration retrieved from the node |
Modify |
Change object configuration |
Edit comments |
Edit object comments |
Manage responsible users |
Modify the list of responsible users for the object |
Access control |
View and modify the object’s access control list |
Create child objects |
Create child objects |
Delete |
Delete the object |
Control |
Execute actions and object tools |
Configure agent |
Change configuration of the agent running on the node |
Upload device configuration |
Upload configuration to the device |
Control maintenance mode |
Enter and leave maintenance mode for the object |
Edit maintenance journal |
Add and modify entries in the object’s maintenance journal |
Manage policies |
Manage agent policies (template objects) |
Send events |
Send events on behalf of the object |
Push data |
Push DCI data for the object |
View alarms |
View alarms related to the object |
Update alarms |
Acknowledge and resolve alarms related to the object (terminating requires the separate Terminate alarms right) |
Terminate alarms |
Terminate alarms related to the object |
Create helpdesk tickets |
Create helpdesk tickets for alarms |
Manage incidents |
Create and manage incidents for the object |
Download files |
Download files from the managed node |
Upload files |
Upload files to the managed node |
Manage files |
Manage files on the managed node (rename, delete) |
Query web service |
Execute web service requests through the object |
Take screenshot |
Capture screenshots (for Windows agent) |
Access rights are inherited from parent objects only when the object’s inherit access rights flag is set. Even then, the parent objects' ACLs are consulted only if the user has no direct ACL entry on the object itself — a direct entry fully replaces inherited rights. If an object has multiple parents, rights inherited from them are combined (OR-ed).
Account Lockout Variables
| Variable | Default | Description |
|---|---|---|
|
0 |
Failed login attempts before lockout (0=disabled) |
|
30 |
Lockout duration in minutes |
Password Policy Variables
| Variable | Default | Description |
|---|---|---|
|
0 |
Minimum password length (0=no minimum); applies only when no per-user minimum password length is set in the user’s properties |
|
0 |
Required password complexity as a bitmask (see below) |
|
0 |
Password expiration time in days (0=never expires) |
|
0 |
Number of previous passwords to keep; users cannot reuse any password in the history |
The PasswordComplexity value is a bitmask constructed by adding the following flags:
| Flag | Requirement |
|---|---|
1 |
Password must contain at least one digit (0-9) |
2 |
Password must contain at least one uppercase letter (A-Z) |
4 |
Password must contain at least one lowercase letter (a-z) |
8 |
Password must contain at least one special character (e.g., |
16 |
Forbid alphabetical sequences (3 or more consecutive letters in the same case, e.g., "abc") |
32 |
Forbid keyboard sequences (3 or more characters adjacent on the keyboard, e.g., "qwe" or "!@#") |
For example, to require digits, uppercase letters, and special characters, set PasswordComplexity to 1 + 2 + 8 = 11.
MinPasswordLength, PasswordComplexity, and PasswordHistoryLength are enforced only when users change their own password. An administrator setting another user’s password bypasses all password policy checks.
|
LDAP Configuration Variables
| Variable | Default | Description |
|---|---|---|
|
|
LDAP server URI; use |
|
(empty) |
DN or UPN of the service account for LDAP queries |
|
(empty) |
Password for the sync account |
|
(empty) |
Base DN for user/group search (e.g., |
|
(empty) |
LDAP search filter string applied when querying for users and groups |
|
0 |
Sync interval in minutes (0=manual sync only) |
|
(empty) |
LDAP object class for users |
|
(empty) |
LDAP object class for groups |
|
(empty) |
LDAP attribute mapped to NetXMS login name |
|
|
LDAP attribute mapped to display name |
|
(empty) |
LDAP attribute mapped to description |
|
(empty) |
LDAP attribute mapped to email address |
|
(empty) |
LDAP attribute mapped to phone number |
|
(empty) |
LDAP attribute mapped to NetXMS group name |
|
(empty) |
LDAP attribute used as unique identifier for users (default: DN); recommended: |
|
(empty) |
LDAP attribute used as unique identifier for groups (default: DN); recommended: |
|
1 |
Action when LDAP user is deleted: 0=delete from NetXMS, 1=disable in NetXMS |
|
5 |
Authentication method assigned to newly created LDAP users (5 = LDAP password) |
|
1000 |
Number of records per LDAP search page (for paged result control) |
Setting LDAP.UserUniqueId and LDAP.GroupUniqueId is recommended. Without it, the DN is used as the unique identifier, and moving a user or group to a different OU in the LDAP directory will cause NetXMS to treat it as a deletion and re-creation.
|
RADIUS Configuration Variables
| Variable | Default | Description |
|---|---|---|
|
|
Hostname or IP address of primary RADIUS server; the literal value |
|
|
Shared secret for primary RADIUS server |
|
1645 |
Authentication port for primary RADIUS server |
|
|
Hostname or IP address of secondary (failover) RADIUS server; the literal value |
|
|
Shared secret for secondary RADIUS server |
|
1645 |
Authentication port for secondary RADIUS server |
|
PAP |
Authentication method: |
|
5 |
Number of retries on timeout |
|
3 |
Response timeout in seconds |
|
(empty) |
Value for the NAS-Identifier attribute in RADIUS requests; if empty, the attribute is not sent |
|
8 |
Value for the Service-Type attribute in RADIUS requests (0=do not include attribute) |
Two-Factor Authentication Variables
| Variable | Default | Description |
|---|---|---|
|
false |
Enforce two-factor authentication for every user regardless of group membership (individual users can still be exempted via the account flag). Checked before the per-group enforcement flags. |
|
0 |
Time-to-live for trusted device tokens (seconds; 0 = require 2FA every login) |
|
120 |
Time in seconds the user has to respond to a 2FA challenge before the client cancels the prompt; 0 disables the auto-cancel timer. The server itself does not expire the challenge. |
|
5 |
Grace logins allowed when 2FA is enforced for a user but no 2FA method is configured at all; after they are used up, 2FA setup becomes mandatory. Read as the fallback default for a per-user counter. |
CAS Configuration Variables
| Variable | Default | Description |
|---|---|---|
|
|
CAS server hostname |
|
8443 |
CAS server port |
|
|
URL path for CAS ticket validation |
|
Service identifier sent to CAS server during validation |
|
|
(empty) |
Path to CA certificate file for validating the CAS server’s SSL certificate |
|
(empty) |
Comma-separated list of allowed CAS proxy server addresses; required if using proxy authentication |
Configuration changes take effect immediately without a server restart. The CAS server validates both service tickets (ST-) and proxy tickets (PT-). The validated user principal name is matched against NetXMS user login names.
Certificate Mapping Methods
Each user configured for certificate authentication must have a mapping method and mapping data set in their user properties.
| Method | Description |
|---|---|
Subject |
The full certificate subject (Distinguished Name) must match the mapping data (case-insensitive comparison) |
Public Key |
The certificate’s public key must match the mapping data (hex-encoded public key data) |
Common Name |
The Common Name (CN) field of the certificate subject must match the mapping data; if mapping data is empty, the CN is compared against the user’s login name |
Template ID |
The certificate template ID (Microsoft AD CS) must match the mapping data |
| The management client offers only Subject, Public key, and Common name; the Template ID method is supported by the server but cannot be selected from the UI. |
UI Access Rule Evaluation
Access rules are stored as a semicolon-separated list and are case-insensitive (lowercased before matching).
Each rule has the form type:id, optionally preceded by a prefix (see below), where type is p (or perspective), v (or view), or .
A rule without a colon is silently ignored.
or : matches all UI elements, and the id part supports * and ? wildcards.
Rules are evaluated in order of priority using prefixes:
| Prefix | Type | Description |
|---|---|---|
|
Priority inclusion |
Highest priority; if matched, the element is always visible regardless of other rules |
|
Exclusion |
If matched, the element is hidden |
(none) |
Inclusion |
If matched, the element is visible |
When determining whether a UI element is visible for a user, all rules from the user account and all groups the user belongs to are combined, then evaluated — rules for the element’s specific category (p: or v:) are consulted before *-category rules at each priority level:
-
Priority inclusions for the element’s category — if any match, the element is visible
-
Exclusions for the element’s category — if any match, the element is hidden
-
Priority inclusions in the
*category — if any match, the element is visible -
Exclusions in the
*category — if any match, the element is hidden -
A match-all inclusion (
or:*) makes the element visible -
Inclusions for the element’s category — if any match, the element is visible
-
Inclusions in the
*category — if any match, the element is visible -
If no rules matched, the element is hidden
Note the consequence of this ordering: a category-specific exclusion (!v:foo) overrides a wildcard-category priority inclusion (^*:foo).
Audit Log Variables
| Variable | Default | Description |
|---|---|---|
|
|
External syslog server hostname or IP address; the literal value |
|
514 |
UDP port for external syslog server |
|
13 |
Syslog facility code for audit messages |
|
5 |
Syslog severity level for audit messages |
|
|
Syslog tag prefix for audit messages |
|
false |
Send audit messages to the external syslog server in UTF-8 encoding |
|
90 |
Number of days to retain internal audit records (purged by housekeeper) |
Changes to AuditLog.External.* variables take effect only after a server restart, except AuditLog.External.UseUTF8, which is applied immediately.
|