SCOM 2019 role based access and delegation

Joseph Patrick 641 Reputation points
2020-09-24T20:32:47.457+00:00

We are standing up SCOM 2019 and we want to give people the operator role, however; they will also need to install/ uninstall agents from the scom management console.

Is it possible to create a delegated role based access structure to give a group the ability to have the rights of the operator role and the ability to install/ uninstall agents?

I have read the link below and only full administrators have the right to install/ uninstall from the console and that is to much rights for a group that we do not want to have.

https://learn.microsoft.com/en-us/system-center/scom/manage-security-create-runas-account?view=sc-om-2019

Operations Manager
Operations Manager
A family of System Center products that provide infrastructure monitoring, help ensure the predictable performance and availability of vital applications, and offer comprehensive monitoring for datacenters and cloud, both private and public.
1,419 questions
0 comments No comments
{count} votes

Accepted answer
  1. Leon Laude 85,666 Reputation points
    2020-09-25T05:23:41.973+00:00

    Hi @Joseph Patrick ,

    Unfortunately you will require SCOM Administrator rights to install, uninstall or delete SCOM agents from the SCOM.

    Feedback is however always welcome, you may submit feedback over at the SCOM uservoice page over here:
    https://systemcenterom.uservoice.com/forums/293064-general-operations-manager-feedback

    ----------

    (If the reply was helpful please don't forget to upvote or accept as answer, thank you)

    Best regards,
    Leon

    0 comments No comments

4 additional answers

Sort by: Most helpful
  1. CyrAz 5,181 Reputation points
    2020-09-24T21:41:44.103+00:00

    That is unfortunately correct, you will have to find another way to deploy the agents (SCCM for example).

    0 comments No comments

  2. Joseph Patrick 641 Reputation points
    2020-09-24T21:49:20.277+00:00

    We are doing a commandline remote push install so that will not be a issue, we are concerned with the uninstall. They can uninstall the agent from the server but the SCOM console will still have the object, is there a way to give them the right to uninstall the agent or delete it from the console without giving them full admin rights?

    0 comments No comments

  3. AlexZhu-MSFT 5,551 Reputation points Microsoft Vendor
    2020-09-25T08:28:37.17+00:00

    Hi,

    Yes, this is by design. To manage operations manager agents, we need administrator privilege. We may fire this up at the user voice and hope product team may include this feature in future release.

    https://systemcenterom.uservoice.com/forums/293064-general-operations-manager-feedback

    Hope the above information helps.

    Alex Zhu


    If the response is helpful, please click "Accept Answer" and upvote it.

    0 comments No comments

  4. CyrAz 5,181 Reputation points
    2020-09-25T11:36:02.087+00:00

    Now if you want to try something very unsupported, you can have a look at how AzMan (Authorization Manager) works. This is the component that actually handles RBAC for SCOM, and where you can edit the roles at a very granular level.
    Have a look here for a short intro on how to manage it : https://kevinholman.com/2014/03/12/modifying-access-in-scom-user-roles-without-the-console/
    But if you wan't my advice on this : simply don't touch it and find another way to achieve what you need.

    You say you use a scripted push install... You can do scripted uninstall or delete just as fine, for example.