ABCDEFGHIJKLMNOPQRSTUVWXYZAAABACADAEAF
1
To use this planning sheet, click File > Make a Copy. To plan security policy configuration for different folder levels, on the bottom tab, right-click, and select Duplicate.
2
Security Policy Planning Sheet
3
4
Last updated 4.27.23 by ControlUp.
5
6
7
For more information on Security Policy configuration, seeSecurity Policy OverviewDEFAULT USER ROLES cannot be deleted, but can be edited or renamed.
8
InheritLocal Admins Organization MembersControlUp Monitors Automation Admins HelpdeskControlUp Admins Custom Role 1 Custom Role 2 Custom Role 3 Custom Role 4 Custom Role 5
9
FOLDER: ROOTAction Definition
10
Perform organization-wide actions Action performed at the organizational level, not in the context of a specific machine, user session, or process.
11
Change PermissionsModify the access and management permissions for users in your environment.
Note: As a security precaution. your organization's owner(s) can always change the permissions
N/ANot SetNot SetNot SetNot SetAllowNot SetNot SetNot SetNot SetNot Set
12
Change Settings
Modify settings such as: presets, agent, AD Connections, schedule, monitors, Virtual Expert, auditing.N/ANot SetN/ANot SetNot SetAllowNot SetNot SetNot SetNot SetNot Set
13
Manage data upload settingsModify data upload and incident reporting settings on the Data Upload tab of the Settings Window.N/ANot SetNot SetNot SetNot SetAllowNot SetNot SetNot SetNot SetNot Set
14
Use Web ApplicationLaunch and use Web Application interface for your organization.N/ANot SetNot SetNot SetNot SetAllowNot SetNot SetNot SetNot SetNot Set
15
Manage Web ApplicationModify Web Application settings of your organization.N/ANot SetNot SetNot SetNot SetAllowNot SetNot SetNot SetNot SetNot Set
16
Edit Stress SettingsModify who is able to edit the Stress Settings.N/ANot SetNot SetNot SetNot SetAllowNot SetNot SetNot SetNot SetNot Set
17
Manage branch mapping settingsConfigure the lookup table of client IP addresses to branch office names in
the Settings window.
N/ANot SetNot SetNot SetNot SetAllowNot SetNot SetNot SetNot SetNot Set
18
Configure Incident TriggersConfigure Incident TriggersN/ANot SetNot SetNot SetNot SetAllowNot SetNot SetNot SetNot SetNot Set
19
Create Automated ActionsCreate Automated ActionsN/ANot SetNot SetAllowNot SetAllowNot SetNot SetNot SetNot SetNot Set
20
Add MachineAdd a managed machine to the organizational tree view.N/ANot SetNot SetNot SetNot SetAllowNot SetNot SetNot SetNot SetNot Set
21
Add FolderAdd a folder in the organizational tree view to arrange similar machines.N/ANot SetNot SetNot SetNot SetAllowNot SetNot SetNot SetNot SetNot Set
22
Change Folder DescriptionChange description for folder.N/ANot SetNot SetNot SetNot SetAllowNot SetNot SetNot SetNot SetNot Set
23
Remove MachineRemove a managed machine from the organizational tree.N/ANot SetNot SetNot SetNot SetAllowNot SetNot SetNot SetNot SetNot Set
24
Remove FolderRemove a folder from the organizational tree view.N/ANot SetNot SetNot SetNot SetAllowNot SetNot SetNot SetNot SetNot Set
25
Rename FolderRename a machine folder in the organizational tree view.N/ANot SetNot SetNot SetNot SetAllowNot SetNot SetNot SetNot SetNot Set
26
Run shared Script ActionsPerform all of the actions in this category on shared Script objects in the current container.N/ANot SetNot SetNot SetNot SetAllowNot SetNot SetNot SetNot SetNot Set
27
Run draft Script ActionsPerform all of the actions in this category on draft Script objects in the current container.N/ANot SetNot SetNot SetNot SetAllowNot SetNot SetNot SetNot SetNot Set
28
Download and share Script ActionsDownload and share Script Actions.N/ANot SetNot SetNot SetNot SetAllowNot SetNot SetNot SetNot SetNot Set
29
Manage Script ActionsManage Script Actions.N/ANot SetNot SetNot SetNot SetAllowNot SetNot SetNot SetNot SetNot Set
30
View FolderView folder in the organizational tree view.N/AAllowNot SetNot SetNot SetAllowNot SetNot SetNot SetNot SetNot Set
31
Launch ControllersWork in Controllers pane. You can only configure this permission on the root folder.N/ANot SetNot SetNot SetNot SetAllowNot SetNot SetNot SetNot SetNot Set
32
View IncidentsView Incidents pane.N/ANot SetNot SetNot SetAllowAllowNot SetNot SetNot SetNot SetNot Set
33
View EventsView Events pane.N/ANot SetNot SetNot SetAllowAllowNot SetNot SetNot SetNot SetNot Set
34
View All HypervisorsView all hypervisor related objects (VMS. Hosts, and hypervisor connections) in your organization.N/ANot SetNot SetNot SetAllowAllowNot SetNot SetNot SetNot SetNot Set
35
Manage All HypervisorsCreate, edit, and delete hypervisor connections in your organization.N/ANot SetNot SetNot SetNot SetAllowNot SetNot SetNot SetNot SetNot Set
36
Manage All Cloud ConnectionsCreate, edit, and delete cloud connections in your organization.N/ANot SetNot SetNot SetNot SetAllowNot SetNot SetNot SetNot SetNot Set
37
Manage All EUC EnvironmentsCreate, edit, and delete EUC Environment connections in your organization.N/ANot SetNot SetNot SetNot SetAllowNot SetNot SetNot SetNot SetNot Set
38
Manage All NetScaler AppliancesCreate, edit, and delete NetScaler connections in your organization.N/ANot SetNot SetNot SetNot SetAllowNot SetNot SetNot SetNot SetNot Set
39
Manage application load time settingsConfigure the parameters ControlUp Agent uses when measuring application load times.N/ANot SetNot SetNot SetNot SetAllowNot SetNot SetNot SetNot SetNot Set
40
Manage Monitor
Perform management taks for ControlUp Monitors.N/ANot SetNot SetNot SetNot SetAllowNot SetNot SetNot SetNot SetNot Set
41
Manage application title settings Configure the parameters the ControlUp agent uses to monitor the title of active windows.N/ANot SetNot SetNot SetNot SetAllowNot SetNot SetNot SetNot SetNot Set
42
Manage browser URL settingsConfigure the parameters the ControlUp agent uses to monitor the URLs of browser processes.N/ANot SetNot SetNot SetNot SetAllowNot SetNot SetNot SetNot SetNot Set
43
Connect to Data SourceCollect data from an external data source. such as hypervisor, XenDesktop site, NetScaIer appliance, or public cloud.N/ANot SetNot SetNot SetNot SetAllowNot SetNot SetNot SetNot SetNot Set
44
Shared CredentialsPerform all actions related to Shared Credentials. Some can be granted only for non-built-in roles.
45
CredentialsAssign permissions for shared credentials in your environment. If you set "Deny" or "Not Set", then a user in this role won't be able to use this permission in any script or automated action. If credentials are configured for a hypervisor. EUC environment, etc. in a specific monitor site, we recommend to set "Alow" only to users from that site.
N/AAllowNot SetNot SetNot SetAllowNot SetNot SetNot SetNot SetNot Set
46
Manage Shared CredentialsCreate, edit, and delete Shared Credentials in your organization. Add the first Shared Credentials: "Monitor Settings", screen -> Choose a monitor in the monitors list -> Click "Settings.." above the monitors list -> Click "Add Credentials Set" -> Keep "Shared" option checked.N/AAllowNot SetNot SetNot SetAllowNot SetNot SetNot SetNot SetNot Set
47
Use Shared CredentialsConnect to an organizational tree view connection with Shared Credentials. Can be granted only for non-built-in roles.N/ANot SetNot SetNot SetAllowAllowNot SetNot SetNot SetNot SetNot Set
48
49
50
Run Host ActionsPerform all of the actions in this category on Host objects in the current container.
51
Enable Maintenance ModeEnter a certain host into Maintenance Mode.N/ANot SetNot SetNot SetNot SetAllowNot SetNot SetNot SetNot SetNot Set
52
Disable Maintenance ModeRemove a certain host from Maintenance Mode.N/ANot SetNot SetNot SetNot SetAllowNot SetNot SetNot SetNot SetNot Set
53
54
55
Run Machines Actions Performs all of the actions in this category on machine objects in the current container.
56
Connect to Windows MachineConnect to Windows machine.Not SetNot SetNot SetNot SetAllowAllowNot SetNot SetNot SetNot SetNot Set
57
Change Machine DescriptionChange description for machine.N/ANot SetNot SetNot SetNot SetAllowNot SetNot SetNot SetNot SetNot Set
58
Event Viewer on Remote Machine*
Open the event viewer of the remote machine.
*Note: This action requires RPC access and valid administrative credentials on the target machines(s).
N/ANot SetNot SetNot SetNot SetAllowNot SetNot SetNot SetNot SetNot Set
59
RDP to MachineSwitch to Remote Desktop view and establishes an RDP connection.N/ANot SetNot SetNot SetNot SetAllowNot SetNot SetNot SetNot SetNot Set
60
ControlUp Agent ManagementPerform all of the actions related to Control Up agent components.
61
Disable Outbound CommunicationDisable outbound communication at the selected machine.
N/ANot SetNot SetNot SetNot SetAllowNot SetNot SetNot SetNot SetNot Set
62
Enable Outbound CommunicationDisable outbound communication at the selected machine.
N/ANot SetNot SetNot SetNot SetAllowNot SetNot SetNot SetNot SetNot Set
63
Install Remote Agent as Master Image*
Install the remote agent as a master image at the selected machine.
*Note: This action requires RPC access and valid administrative credentials on the target machine(s).
N/ANot SetNot SetNot SetNot SetAllowNot SetNot SetNot SetNot SetNot Set
64
Start Remote Agent*
Starts the remote agent at the selected machine.
*Note: This action requires RPC access and valid administrative credentials on the target machine(s).
N/ANot SetNot SetNot SetNot SetAllowNot SetNot SetNot SetNot SetNot Set
65
Stop Remote Agent*
Stops the remote agent at the selected machine.
*Note: This action requires RPC access and valid administrative credentials on the target machine(s).
N/ANot SetNot SetNot SetNot SetAllowNot SetNot SetNot SetNot SetNot Set
66
Restart Remote Agent*
Restart the remote agent at the selected machine.
*Note: This action requires RPC access and valid administrative credentials on the target machine(s).
N/ANot SetNot SetNot SetNot SetAllowNot SetNot SetNot SetNot SetNot Set
67
Remove Remote Agent*
Remove the remote agent from the selected machine.
*Note: This action requires RPC access and valid administrative credentials on the target machine(s).
N/ANot SetNot SetNot SetNot SetAllowNot SetNot SetNot SetNot SetNot Set
68
Upgrade/Install Remote Agent*
Upgrade the remote agent at the selected machine.
*Note: This action requires RPC access and valid administrative credentials on the target machine(s).
N/ANot SetNot SetNot SetNot SetAllowNot SetNot SetNot SetNot SetNot Set
69
Listening Port Remote Agent*
Set the listening port for the remote agent at the selected machine.
*Note: This action requires RPC access and valid administrative credentials on the target machine(s).
N/ANot SetNot SetNot SetNot SetAllowNot SetNot SetNot SetNot SetNot Set
70
VM Power ManagementControl power management of virtual machines.
71
Shutdown GuestGracefully shut down the virtual machine.N/ANot SetNot SetNot SetNot SetAllowNot SetNot SetNot SetNot SetNot Set
72
Force Power Off VMForcefully power off the virtual machine.N/ANot SetNot SetNot SetNot SetAllowNot SetNot SetNot SetNot SetNot Set
73
Restart GuestGracefully restart the virtual machine.N/ANot SetNot SetNot SetNot SetAllowNot SetNot SetNot SetNot SetNot Set
74
Force Reset VMForcefully reset the virtual machine.N/ANot SetNot SetNot SetNot SetAllowNot SetNot SetNot SetNot SetNot Set
75
Power On VMPower on the virtual machine on the hypervisor infrastructure.N/ANot SetNot SetNot SetNot SetAllowNot SetNot SetNot SetNot SetNot Set
76
Enable Remote Assistance in Group PolicyRemove the unsolicited remote assistance restriction on the target machine.Not SetNot SetNot SetNot SetNot SetAllowNot SetNot SetNot SetNot SetNot Set
77
Flush DNSFlush DNS on the selected machine.Not SetNot SetNot SetNot SetNot SetAllowNot SetNot SetNot SetNot SetNot Set
78
Install Remote Assistance FeatureInstall Remote Assistance Feature.Not SetNot SetNot SetNot SetNot SetAllowNot SetNot SetNot SetNot SetNot Set
79
File SystemPerform all file-system related actions in this category.
80
Manage File SystemPerform actions on file system objects.
*Note: This action requires RPC access and valid administrative credentials on the target machine(s).
Not SetNot SetNot SetNot SetNot SetAllowNot SetNot SetNot SetNot SetNot Set
81
Monitor File SystemView, analyze, and compare file-system objects.Not SetNot SetNot SetNot SetNot SetAllowNot SetNot SetNot SetNot SetNot Set
82
Group PolicyPerform all group policy-related actions in this category.
83
Refresh Machine PolicyRefresh the machine group policy using the command 'gpupdate.exe /target: machine'Not SetNot SetNot SetNot SetNot SetAllowNot SetNot SetNot SetNot SetNot Set
84
Installed SoftwareView information about the software package currently installed.
85
Display Installed SoftwareDisplay information about currently installed programs.Not SetNot SetNot SetNot SetNot SetAllowNot SetNot SetNot SetNot SetNot Set
86
Display Installed UpdatesDisplay information about currently installed updates.Not SetNot SetNot SetNot SetNot SetAllowNot SetNot SetNot SetNot SetNot Set
87
Power ManagementPerform all power management tasks in this category.
88
ShutdownShutsdown the selected machine.Not SetNot SetNot SetNot SetNot SetAllowNot SetNot SetNot SetNot SetNot Set
89
RebootRestart the selected machine.Not SetNot SetNot SetNot SetNot SetAllowNot SetNot SetNot SetNot SetNot Set
90
Wake-On-LANSend a Wake-On-LAN magic packet to wake up the machine.Not SetNot SetNot SetNot SetNot SetAllowNot SetNot SetNot SetNot SetNot Set
91
ProcessesExecute processes on the managed machine.
92
Start Process As UserStars a new process on the target machine, with the supplied credentials, or with the remote agent credentials.Not SetNot SetNot SetNot SetNot SetAllowNot SetNot SetNot SetNot SetNot Set
93
Enable Process ExecutionEnable a process execution.Not SetNot SetNot SetNot SetNot SetAllowNot SetNot SetNot SetNot SetNot Set
94
Disable Process ExecutionDisable a process execution.Not SetNot SetNot SetNot SetNot SetAllowNot SetNot SetNot SetNot SetNot Set
95
RegistryPerform all registry-related actions in this category.
96
Import Registry MachineImport a registry key from a file. Type a file name or browse for a registry file to import.Not SetNot SetNot SetNot SetNot SetAllowNot SetNot SetNot SetNot SetNot Set
97
Modify Machine RegistryPerform registry actions on machines in this container.Not SetNot SetNot SetNot SetNot SetAllowNot SetNot SetNot SetNot SetNot Set
98
‬Monitor Machine RegistryAnalyze and compare registry settings on machines in this container.Not SetNot SetNot SetNot SetNot SetAllowNot SetNot SetNot SetNot SetNot Set
99
ServicesPerform all service-related actions in this category.
100
Manage ServicesPerform system service actions on machines in this container.Not SetNot SetNot SetNot SetNot SetAllowNot SetNot SetNot SetNot SetNot Set