Platform Secure Firewall Threat Defense Virtual
Activity Manage

Manage Role Delegation

As an organization administrator, you can now delegate the product administrator privileges to any user. This delegated product administrator role grants the user access to both—the management of administrators, admin roles, and admin groups, and the administrative privileges solely for the designated product.

As a delegated product administrator, you can log in to Security Cloud Control to perform these role-based access control operations:

On this menu...

You have administrative access to...

Platform Management > Access Management > Administrator Access > Administrators

  • View all the users that are part of the managed product.

  • Edit the roles and groups that are associated with a user.

  • Invite users to the system either through the Invite menu or through the Import menu.

  • Remove users from the managed product.

    If an administrator is part of another group for a different product, you can’t remove such users.

  • Add users to groups or remove users from the groups that are associated with the managed product. If a group has users and roles of other products, you can’t access such users.

  • Reset passwords and MFA for users within the managed product.

  • Assign or unassign roles to users of the managed product.

  • Disable user account for the managed product.

  • Restore user account for the managed product.

Platform Management> Access Management > Administrator Access > Admin groups

  • Create a group for the users of the managed product.

    A newly created group can have only those roles that are part of the managed product.

  • View details of a group.

    If a group has roles for a product that you don't manage, such roles are not displayed in the Group Detail page.

  • Add users to groups or remove users from groups that have roles within the managed product.

  • Assign product roles to groups within the managed product.

Platform Management> Access Management > Administrator Access > Admin roles

  • View roles that are available for the product.

  • Assign roles to or remove roles from users of the managed product.

  • Assign roles to or remove roles from groups that are created for the managed product.

The Roles page displays all roles for the products that you manage.

A purple icon next to a role in the roles list indicates that it is a delegated role.

The Role details page lists the users and groups for the roles (static and custom) of the managed product.