Administrative user account field descriptions

Last Updated : Mar 23, 2026 |

Name

Description

User Name

The system-assigned name for the account owner.

Real Name

The actual name of the individual for whom the account is being created.

Contact Information

The contact details of the account owner, such as email address and phone number.

Type

The authentication method for the user. Options include the following:

  • Local: Authenticates the user through the local administrative control of Avaya SBC.

  • LDAP: Authenticates the user through the Active Directory system of the customer. LDAP users must also exist in the Active Directory, and the directory must be linked to Avaya SBC.

    This option is available only if LDAP is enabled on the Administration Parameters tab. When you select LDAP, the Password, Confirm Password, and Force Password Change on Next Login fields are disabled.

  • RADIUS: Authenticates the user through a Remote Authentication Dial-In User Service (RADIUS) server.

    This option is available only if a RADIUS server is configured and RADIUS is enabled on the Administration Parameters tab. When you select RADIUS, the Password, Confirm Password, and Force Password Change on Next Login fields are disabled.

  • ASG: A display-only option that identifies a user authenticated through EASG.

    You cannot change this option.

Password

The password for the user.

This field is disabled for LDAP, RADIUS, and EASG accounts.

Confirm Password

The confirmation password for the user.

This field is disabled for LDAP, RADIUS, and EASG accounts.

Force Password Change on Next Login

The option to require the user to create a new password at their next login.

This field is disabled for LDAP, RADIUS, and EASG accounts.

Allow X.509 Authentication

The option to enable X.509 authentication for the user account.

This field is available only if X.509 is enabled on the Administration Parameters tab.

Authentication Mode

The X.509 authentication mode. Options include the following:

  • Inherit from AAA Settings: Authenticates the user based on the global authentication mode settings. For more information, see X.509 certificate authentication field descriptions.

  • Accept X.509 Certificate or Password: Authenticates the user if a valid certificate or a valid password is provided.

  • Require X.509 Certificate: Authenticates the user only if a valid certificate is provided. Any password the user enters is ignored.

  • Require X.509 Certificate and Password: Authenticates the user only if a valid certificate and a valid password are provided.

Accepted Common Names

Common names that are accepted when authenticating an X.509 certificate. The list of names must be separated by a new-line character.

Role

The level of administrative access to the account. Options include the following:

  • System Administrator (default): Has full read/write permissions for Avaya SBC security features, including the ability to add, edit, and delete other administrative accounts.

  • System Engineer: Has the same privileges as System Administrator, except they cannot add or modify user accounts.

  • Service Administrator: Has the same privileges as System Administrator, but cannot add new accounts. Service Administrator can only view TLS and firewall settings.

  • Security Administrator: Can manage system users, TLS, and firewall settings.

  • FIPS 140–2 Crypto Officer: Can only view and manage TLS settings.

  • Auditor: Has read-only access to view incident and statistical logs.

  • Backup Administrator: Can create and restore system snapshots.

  • External Users Administrator: Can only manage external users. External users are authenticated using LDAP or a remote RADIUS server.

Status

The current status of the user account. Options include the following:

  • Normal

  • Disabled

  • Locked

  • Expired

You cannot change the status of the user to Locked. The EMS server is set after multiple unsuccessful login attempts.

Note:

Disabling a user account or changing its role disconnects all clients connected to that user account.