This page describes managing a user in the Cisco AppDynamics SaaS Controller Tenant UI. 

User management through the Controller Tenant UI affects that Tenant only. You can use the Account Management Portal to manage the global aspects of Cisco AppDynamics user accounts. See Global Accounts Administration.

What is a Controller Tenant?

A Cisco AppDynamics Controller can host one or more accounts. Each account represents one Tenant on that Controller.

The Cisco AppDynamics cloud-based Software as a Service (SaaS) deployment is a multi-tenant environment that allows you to access multiple Controller Tenants independently. Every Cisco AppDynamics SaaS Controller Tenant has one license associated with it.

You can manage users and add user accounts in the Controller Tenant UI, allowing other users to access the Tenant and configure Cisco AppDynamics

Role-Based Access Control (RBAC) Overview

Cisco AppDynamics uses Role-Based Access Control (RBAC) to set user permissions and privileges for only those functions necessary in defined job responsibilities. Each user account can have varying levels of access based on their role(s). See Manage Custom Roles for Cisco AppDynamics.

The Controller Tenant can authenticate users against local user accounts or external LDAP or SAML-based authentication providers. The user account for a Controller Tenant user authenticates through the AppDynamics Identity Provider (IDP) in the cloud rather than by an external authentication provider. See External Authentication for SaaS Deployments

group is a collection of users with a given set of permissions that apply to the users in the group. You can use groups to manage roles collectively 

role is a collection of permissions that define what actions a user can perform; RBAC. When you assign a role to a user, they inherit the role permissions. A user's group membership and role remain constant for the duration of their login. 

Permissions grant users the ability to perform an action on the platform. You can set permissions at a granular level to determine:

  • The business applications the user can monitor.
  • The parts of the UI that are visible.
  • Types of configurations a user can make.

Cisco AppDynamics University offers courses in Administrator functions.

Controller Tenant User Management Overview

Cisco AppDynamics user credentials for both SaaS and on-premises deployments are managed according to the authentication options selected in Settings> Administration > Authentication Provider. There are three user authentication options:

Authentication ProviderUser TypeDescription
AppDynamicsLocal User

Managing a Local User through the Controller Tenant UI affects permissions for that Controller Tenant only. The user account retains Active status with existing permissions on other associated Controller Tenants. Use the Account Management Portal to fully deactivate or edit an account for all Cisco AppDynamicscomponents and Controller Tenants simultaneously. 

  • Users authenticate through AppDynamics IDP for SaaS deployment.
  • AppDynamics manages user account credentials. 
  • Can exist in parallel and access the system even when using SAML and LDAP authentication.
LDAPLDAP User
  • Users authenticate through your IDP.
  • You manage user account credentials through LDAP integration. 
  • Non-LDAP users cannot access the system unless they have also been set up as a Local User.
SAMLSAML User
  • Users authenticate through your IDP using the SAML 2.0 protocol.
  • You manage user account credentials through SAML integration.
  • Non-SAML users cannot access the system unless they have also been set up as a Local User.

With Cisco AppDynamics SaaS, when you add a new local user through the Controller Tenant UI, an email is sent to that user's valid address prompting them to create their own profile name and password. The user's email serves as their username. Only the account user can create their own password. Once completed, an account with the proper credentials is added to the Controller Tenant and authenticated through the AppDynamics IDP providing the user unified access to the Account Management PortalUniversityCommunity, and role-specific functions on the Controller Tenant UI. 

With an on-premises deployment, when you add a new local user through the Controller Tenant UI, an account with the proper credentials is created and stored on that Controller Tenant.

You can create and manage users, groups, roles, and permissions on the corresponding page through Settings> Administration. See Manage Controller Tenant Users and Groups and Manage Custom Roles for Cisco AppDynamics.