DPM 2012 – Centralized Management : Role Based Access Control
Published Feb 15 2019 08:05 AM 1,084 Views
First published on TECHNET on Sep 08, 2011

Most enterprises have a centralized team which amongst other responsibilities also handles running of the backup service in their organization. It is a considerable challenge to effectively delegate work to the various support teams while retaining control over the DPM environment.

With DPM 2012, you can effectively model your existing team structure into one of the roles shipped out of the box. The Role Based Access in DPM 2012 works at the “Operation” level and NOT “object” level. For example, you can control who can run backups versus who can run recoveries. But once you allow a user to perform backups, you cannot further control to say “run backups only for these databases.”

Here is a video recording ( DPM 2012 – Centralized Management : Role Based Access ) that talks about Role Based Access and shows how a recovery operator can recover a item from the Central Console in a couple of clicks.

DPM 2012 ships with a rich set of 7 default roles out of the box. This includes:

  • Read-Only User – Can view all. Can modify,run nothing.
  • Recovery Operator – Can only perform Recoveries
  • Reporting Operator – Can only run/manage reports
  • Tier-1 Support (help desk) – Can “Resume backups” and “Take Automated Recommended Action”. Can open a scoped DPM Console to troubleshoot issues.
  • Tier-2 Support(escalation) – Can run backups on demand. Can perform corrective actions such as enabling/disabling agents etc.
  • TAPE Operator – Can rerun backups or perform TAPE drive tasks
  • TAPE Admins – Can perform all TAPE related actions
  • DPM Admins – Can perform all actions.

To get these roles into Operations Manager,

  • Import the management pack,
  • Install the “Central Console Server Side Components” setup.
  • Once this is done, run the tool “DefaultRoleConfigurator.exe” on the Operations Manager Server which can be found under the C:\Program Files\Microsoft DPM\bin folder. This will create the roles inside Operations Manager.

- Prabu Ambravaneswaran | Program Manager | Microsoft Corporation

Version history
Last update:
‎Mar 11 2019 08:52 AM
Updated by: