HP StorageWorks Clustered File System 3.6.0 Windows Storage Server Edition Administration Guide (403103-005, January 2008)

Table Of Contents
Chapter 12: Configure Security Features 144
(NetBIOS-domain\username, DNS-name\username, or isolated
names without domains) will fail if the user account name contains
more than 20 characters. This restriction does not apply to group
account names.
View Effective Rights
The My Rights tab on the Role-Based Security Control Panel lists the
effective rights that you have on the cluster. Effective rights are the sum
of the rights provided by all of the roles to which you belong. Allowed
operations are indicated by a checkmark. Denied operations are indicated
by an X.
The Role memberships pane at the bottom of the My Rights tab shows the
roles to which you belong. Roles that are disabled appear in italics. In the
following example, the user has logged on as a member of the local
Administrators group and is therefore a member of the default System
Administrator role. This group is allowed to perform all cluster
operations. However, the user also belongs to the Deny Storage group,
which disallows the ability to perform storage operations. Because the
deny right overrides the allow right provided to the System
Administrator group, this user is denied the ability to perform storage
tasks.
The Security resource is a special case. All members of the System
Administrator role are allowed to perform Security tasks, even if they
belong to another role that denies that right.
If you belong to the role because you are a member of group that is either
directly or indirectly assigned to the role, that group will be listed under
the Assigned Group column in the Role memberships pane. In this
example, the user belongs to a group (the local Administrators group)
that is a member of the default System Administrator role. For the Deny
Storage role, the users account is a member of the role and there is not an
entry in the Assigned Group column.