System Access; Authentication Model - Xerox WorkCentre 7220 Information

Color laser multifunctional printer
Hide thumbs Also See for WorkCentre 7220:
Table of Contents

Advertisement

WorkCentre 7220-7225 Information Assurance Disclosure Paper

3. System Access

3.1. Authentication Model

The authentication model allows for both local and network authentication and authorization. In the local and
network cases, authentication and authorization take place as separate processes: a user must be authenticated
before being authorized to use the services of the device.
If the device is set for local authentication, user account information will be kept in a local accounts database (see
the discussion in Chapter 4 of Xerox Standard Accounting) and the authentication process will take place locally. The
system administrator can assign authorization privileges on a per user basis. User access to services will be provided
based on the privileges set for each user in the local accounts database. .
When the device is set for network authentication, the user's network credentials will be used to authenticate the user
at the network domain controller.
Users can be authorized on an individual basis to access one or any combination of the available services such as:
Copy, Fax, Server Fax, Reprint Saved Jobs, Email, Internet Fax, Workflow Scanning Server, Extensible Interface
Platform Services.
Also users can be authorized to access one or any combination of the following machine pathways: Services, Job
Status, or Machine Status.
User Permissions, the new authorization method determines your authorization be Role. Roles are stored in the local
account database and users are either directly assigned to the roles in the database, or the role is associated with an
LDAP/SMB group. Once the device determines what group the user is a member of, it determines what roles in the
local database are associated with that group and define access based on the roles. Assignment of users to the
System Administrator role or the Accounting Administrator is also managed via User Permissions.
Figure 3-1 provides a schematic view of the authentication and authorization subsystem. Use of the local accounts
database or the network can be set independently for both authentication and authorization, meaning that it is
possible to enable network authentication and local authorization, or vice versa. Usually the device will be set for
both authentication and authorization to take place against the same database, either local or network.
Ver. 1.0, January 2013
Page 28 of 61

Advertisement

Table of Contents
loading

This manual is also suitable for:

Workcentre 7225

Table of Contents