To further restrict access to Operations Sentinel server resources, the workstation user account or the corresponding shadow account must belong to one or both of two predefined Windows local user groups on the Operations Sentinel server. These groups are named SPO Users and SPO Administrators. If your workstation user account is a member of the SPO Administrators group, you can launch any Operations Sentinel client applications from the workstation and perform administrative tasks. If your workstation user account is a member of the SPO Users group, you can launch any Operations Sentinel client application and perform administration tasks and operations tasks. Any attempt to launch an Operations Sentinel client application using any other account is denied.
During installation of Operations Sentinel on the server, the Windows user account you use for installation is placed in the SPO Administrators group along with the local Administrator account on the server.
In Operations Sentinel, members of the Sentinel Operators role are given the same privileges as the SPO Users role and Administrators are given the same privileges as the SPO Administrators role. In Server Sentinel, the Security Manager assigns the SPO Administrators group to the Administrators role and the SPO Users group to the Sentinel Operators role