Administrative user accounts and authentication modes

Last Updated : Mar 23, 2026 |

You must create administrative user accounts for each individual who requires access to Avaya SBC. Use the procedures in this section to assign users, roles, authentication methods, permissions, password policies, and other access-related parameters.

Roles

You can assign the following standard roles to administrative user accounts:

  • System Administrator: Has full read/write permissions for Avaya SBC security features, including the ability to add, edit, and delete other administrative accounts.

  • System Engineer: Has the same privileges as System Administrator, except they cannot add or modify user accounts.

  • Service Administrator: Has the same privileges as System Administrator, but cannot add new accounts. Service Administrator can only view TLS and firewall settings.

  • Security Administrator: Can manage system users, TLS, and firewall settings.

  • FIPS 140-2 Crypto Officer: Can only view and manage TLS settings.

  • Auditor: Has read-only access to view incident and statistical logs.

  • Backup Administrator: Can create and restore system snapshots.

  • External Users Administrator: Can only manage external users. External users are authenticated using LDAP or a remote RADIUS server.

EASG-Specific roles

For the Avaya Enhanced Access Security Gateway (EASG) feature, the following special roles can be assigned:

  • Avaya Services Administrator: A default role for EASG administrators. Privileges are similar to those of System Administrator accounts.

  • Avaya Services Maintenance and Support: A default role for EASG support users. Privileges are similar to those of Auditor accounts.

Authentication modes

You can use the following modes to authenticate administrative users:

  • Local: Authenticates users through the local administrative control of Avaya SBC.

  • RADIUS: Authenticates users through a Remote Authentication Dial-In User Service (RADIUS) server. The RADIUS server must be configured in Avaya SBC before this authentication method is assigned. For more information, see Adding a RADIUS server.

  • LDAP: Authenticates users through the customer’s Active Directory system. LDAP users must also exist in the Active Directory, and the directory must be linked to Avaya SBC.

  • X.509: A standard that requires all server-based products to support X.509-formatted user certificates for multi-factor authentication (MFA) of administrative users.

  • EASG: Enhanced Access Security Gateway (EASG) provides secure, customer-controlled access for Avaya services personnel. EASG users exist only when the customer grants Avaya access to the system.