Help > Functions and applications > Access authorisations
Access authorisations
The following authorisation levels are available:
Administrator (access with the admin username and admin password)
User (access with the internal user number and with the assigned user password)
In order to prevent important settings from being changed accidentally or by unauthorised people, the PBX can be protected from unauthorised access.
Administrator
The administrator has unrestricted access to the web interface. The PBX can completely be configured and the PINS and passwords of all internal users can be changed with this access.
Users (internal users)
The user is any internal user of the PBX. For each user, a user PIN is generated. The access authorisations to the web interface are assigned to the user by the administrator according to local requirements. The possible range of page releases is limited to a very small number of own user and group settings.
Each user has the same access authorisations. There modification rights may differ depending on the profiles.
Additional app passwords for users
The user password is used for SIP registration and the access to the web interface and API. Therefore, PBX access data must frequently be saved in external systems. This will lead to security risks, if these systems are insufficiently secured.
Therefore, additional user passwords for accessing the web interface or API can be generated.
If an app password has been generated for the user and the corresponding access authorisation has been enabled, the previous user password loses the access authorisation for the correspondig application.
Configuration
Configuring administrator access.
-Administration > Contact information > Administrator access
Configuring PINs and passwords for users.
-User > Phone Number > > Basic Network Settings
Generating additional app passwords (web interface/API) for a user.
-User > Phone Number > > Basic Network Settings
Configuring authorization for controlling of the pbx via phone.
-User > Telephone number > > Authorizations
Password
Password that consists of at least 8 characters containing digits, letters (upper and lower case, but no German umlauts and ß) and special characters - _ . ! ~ * ' ( ) & = + $ ,.
Specific characteristic of the Admin password: Any characters can be used without restrictions.
Passwords with a low security level cannot be saved. A high level does not necessarily indicate a secure password.
* Note: General rule: If the password is complicated, it can be shorter. If a password is longer, it can use simpler character strings. Coloured bars provide direct visual feedback about the password strength when a password is entered.
* Caution: Visible PINs and passwords are a security risk.
PIN
The PIN consists of 6 digits.
All the PINs in the PBX are unique. For this reason, you cannot assign the same PIN twice.
Do not use dates of birth, dates or too easy to guess PINs such as 111111 or 123456.
Setting a user PIN is not absolutely necessary.
* Caution: Visible PINs and passwords are a security risk.