Operations Sentinel Security Diagram

Refer to Figure 1–4 for the relationships between Operations Sentinel security and Windows User security objects in a typical environment.

When a user NA/UserD in domain NA logs onto the Operations Sentinel workstation, NA/UserD can access the Operations Sentinel server and can make changes after clicking the Administration button in Operations Sentinel Console. The server in this diagram is in a separate domain or workgroup that has a trusted relationship with the NA domain. As the workstation user account NA/UserD has a shadow account on the Operations Sentinel server that is a member of the local user group SPO Administrators, Operations Sentinel Console starts successfully. Users SA/UserA, NA/UserB, and SA/UserC cannot make changes after clicking the Administration button because they are not members of SPO Administrators.