Users and their assigned Security Profiles determine who can access your RMS database and what actions they can perform once they have logged in.
Overview
System Administrators should regularly review the active Users in RMS and their assigned Security Profiles to protect the sensitive information stored in the RMS database.
Â
Â
Active Users
In the side menu of RMS, go to Setup > Users > User Information.Â
Review the list of displayed Users and set any that should not have access to RMS as 'Inactive'.
To set a User 'Inactive'Â -
- Select the View 'Active'.
- Select 'Edit' on the identified User.
 - Set the 'Active' toggle to the off position
 - Select a Reason.
- Select 'Save/Exit'.
 - Select 'Save/Exit'.
Â
Security Profiles
Review the level of access each active User has in RMS by checking which Security Profile is assigned.
The 'Profile Name' column on User Information setup will list all Security Profiles assigned to that User and can be used to quickly verify the Security Profile assigned still matches the staff member's role at the property.
Enterprise customers may choose to 'Edit' a user and review the Properties and Security Profiles a user has access to on the 'Profile' tab.
Users should only be assigned a Security Profile with the access level required to perform their duties.
Â
User Audit
- The System Access Report and User Audit Report provide detailed information for user logins and the actions performed in RMS.
- Generate a System Access Report for all users and review the login times and IP addresses to verify user access to RMS.
- If you notice any unusual activity for a user, immediately reset the user's password and review the Security setup in RMS.
|
Tip! Review the Password Policy and enable Two Factor Authentication for an additional layer of security to user login, or use Restricted IP Addresses to limit the IP Addresses that can access your RMS database. |
Â
Comments
0 comments
Please sign in to leave a comment.