210-060 · Question #192
A user in Cisco Unified Communications Manager Administration has been added to the Standard CCM Admin Users group, which includes the Standard CCMADMIN Administration role, but the user cannot add…
The correct answer is C. The add user capability has been disabled for the role. In CUCM, individual capabilities within a role can be enabled or disabled, so even a correctly assigned role may lack the add-user permission if that capability was turned off.
Question
A user in Cisco Unified Communications Manager Administration has been added to the Standard CCM Admin Users group, which includes the Standard CCMADMIN Administration role, but the user cannot add new users. What is the cause of this issue?
Options
- AThe add user capability has been disabled for the group
- BThe incorrect group and role were assigned.
- CThe add user capability has been disabled for the role.
- DOnly the CCMAdmin user can add users.
- EUsers can be added only via LDAP
How the community answered
(36 responses)- A3% (1)
- B17% (6)
- C69% (25)
- D3% (1)
- E8% (3)
Why each option
In CUCM, individual capabilities within a role can be enabled or disabled, so even a correctly assigned role may lack the add-user permission if that capability was turned off.
CUCM does not support disabling capabilities at the group level; capability controls are enforced within roles, not groups.
Standard CCM Admin Users and Standard CCMADMIN Administration are the appropriate group and role for administrative functions, so the assignment itself is correct.
Each role in Cisco Unified Communications Manager contains a set of resources with configurable access levels. Within the Standard CCMADMIN Administration role, individual capabilities such as adding users can be explicitly disabled. If the add-user capability is disabled at the role level, the user cannot add new users regardless of which group or role they belong to.
CUCM has no restriction limiting user creation to a single CCMAdmin account; any user with the correct role permissions can add users.
While LDAP synchronization imports users automatically, administrators can still create users manually in CUCM Administration when the role grants that capability.
Concept tested: CUCM role-based access control capability settings
Source: https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cucm/admin/12_5_1/admin/cucm_b_administration-guide-1251/cucm_m_role-based-access-control.html
Topics
Community Discussion
No community discussion yet for this question.