Predefined user roles
User roles assigned to Kaspersky Security Center users provide them with sets of access rights to application features.
Users created on a virtual Server cannot be assigned a role on the Administration Server.
You can use the predefined user roles with already configured set of rights, or create new roles and configure the required rights yourself. Some of the predefined user roles available in Kaspersky Security Center can be associated with specific job positions, for example, Auditor, Security Officer, Supervisor (these roles are present in Kaspersky Security Center starting from the version 11). Access rights of these roles are pre-configured in accordance with the standard tasks and scope of duties of the associated positions. The table below shows how roles can be associated with specific job positions.
Examples of roles for specific job positions
Role | Comment |
Auditor | Permits all operations with all types of reports, all viewing operations, including viewing deleted objects (grants the Read and Write permissions in the Deleted objects area). Does not permit other operations. You can assign this role to a person who performs the audit of your organization. |
Supervisor | Permits all viewing operations; does not permit other operations. You can assign this role to a security officer and other managers in charge of the IT security in your organization. |
Security Officer | Permits all viewing operations, permits reports management; grants limited permissions in the System management: Connectivity area. You can assign this role to an officer in charge of the IT security in your organization. |
The table below shows the access rights assigned to each predefined user role.
Access rights of predefined user roles
Role | Description |
---|---|
Administration Server Administrator | Permits all operations in the following functional areas:
|
Administration Server Operator | Grants the Read and Execute rights in all of the following functional areas:
|
Auditor | Permits all operations in the functional areas, in General features:
You can assign this role to a person who performs the audit of your organization. |
Installation Administrator | Permits all operations in the following functional areas:
Grants the Read and Execute rights in the General features: Virtual Administration Servers functional area. |
Installation Operator | Grants the Read and Execute rights in all of the following functional areas:
|
Kaspersky Endpoint Security Administrator | Permits all operations in the following functional areas:
Grants the Read and Write rights in the General features: Encryption key management functional area. |
Kaspersky Endpoint Security Operator | Grants the Read and Execute rights in all of the following functional areas:
|
Main Administrator | Permits all operations in functional areas, except for the following areas, in General features:
Grants the Read and Write rights in the General features: Encryption key management functional area. |
Main Operator | Grants the Read and Execute (where applicable) rights in all of the following functional areas:
|
Mobile Device Management Administrator | Permits all operations in the following functional areas:
|
Mobile Device Management Operator | Grants the Read and Execute rights in the General features: Basic functionality functional area. Grants Read and Send only information commands to mobile devices in the Mobile Device Management: General functional area. |
Security Officer | Permits all operations in the following functional areas, in General features:
Grants the Read, Write, Execute, Save files from devices to the administrator's workstation, and Perform operations on device selections rights in the System management: Connectivity functional area. You can assign this role to an officer in charge of the IT security in your organization. |
Self Service Portal User | Permits all operations in the Mobile Device Management: Self Service Portal functional area. This feature is not supported in Kaspersky Security Center 11 and later version. |
Supervisor | Grants the Read right in the General features: Access objects regardless of their ACLs and General features: Enforced report management functional areas. You can assign this role to a security officer and other managers in charge of the IT security in your organization. |
Vulnerability and patch management administrator | Permits all operations in the General features: Basic functionality and System management (including all features) functional areas. |
Vulnerability and patch management operator | Grants the Read and Execute (where applicable) rights in the General features: Basic functionality and System management (including all features) functional areas. |