Installation Manual
Using the iDRAC6 Directory Service 167
  NOTE: The Bit Mask values are used only when setting Standard Schema 
using RACADM.
Single Domain Versus Multiple Domain Scenarios
If all the login users and role groups, and the nested groups, are in the same 
domain, then only the domain controllers’ addresses must be configured on 
iDRAC6. In this single domain scenario, any group type is supported.
If all the login users and role groups, or any of the nested groups, are from 
multiple domains, then Global Catalog server addresses are required to be 
configured on iDRAC6. In this multiple domain scenario, all the role groups 
and the nested groups, if any, must be a Universal Group type.
Configuring Standard Schema Microsoft Active 
Directory to Access iDRAC6
You must perform the following steps to configure Active Directory before an 
Active Directory user can access iDRAC6:
1
On an Active Directory server (domain controller), open the 
Active 
Directory Users and Computers Snap-in.
2
Create a group or select an existing group. Add the Active Directory user 
as a member of the Active Directory group to access the iDRAC6.
Table 7-9. Default Role Group Privileges
 Privilege Level Permissions Granted Bit Mask
Administrator Login to iDRAC, Configure iDRAC, 
Configure Users, Clear Logs, Execute Server 
Control Commands, Access Virtual 
Console, Access Virtual Media, Test Alerts, 
Execute Diagnostic Commands
0x000001ff
Operator Login to iDRAC, Configure iDRAC, 
Execute Server Control Commands, Access 
Virtual Console, Access Virtual Media, Test 
Alerts, Execute Diagnostic Commands
0x000000f9
Read Only Login to iDRAC 0x00000001
None No assigned permissions 0x00000000










