Administrator roles

Prev Next

An administrator role is associated with a specific set of administrative privileges, such as managing users, configuring system settings, or creating and viewing reports. Instead of granting broad, unrestricted access individually, administrator roles group related administrative privileges into clearly defined responsibilities outlining the tasks an administrative user can perform within the system.

Rather than managing the administrative privileges for each administrator account individually, you can configure a set of administrator roles according to your organizational requirements and assign them to the administrator accounts where applicable, ensuring that administrators have only the level of access required to perform their duties.

This allows administrative access to be delegated safely, even in complex or multi‑domain environments. Administrator roles can be assigned, modified, or revoked at any time to reflect organizational changes or security requirements.

Administrator role basics

Administrator roles are additive, meaning that an administrator’s effective administrative privileges include all privileges that are granted by any administrator role assigned to that administrator account.

You can assign multiple administrator roles to an administrator account, and the same administrator role can be assigned to multiple administrator accounts.

Administrator roles and individual privileges

You can either assign administrator roles to an administrator account or assign administrative privileges to it directly, but you cannot use both for the same administrator account. If you assign an administrator role to an account, any previously assigned administrative privileges are automatically removed. If an account has an administrator role assigned, you cannot edit the individual administrative privileges of that account directly anymore.

Depending on your administrative requirements, you can assign administrator roles to some of the administrator accounts while managing administrative privileges directly for others. However, except for very small deployments, we recommend managing administrative access exclusively with administrator roles rather than assigning individual privileges directly.

If you unassign the last administrator role from an administrator account, the account has no longer any administrative privileges, and is effectively demoted to a regular user account.

Administrator roles and administrative scope

Administrator roles are defined globally and are independent of the administrative scope, which is determined by where the administrator account is located within the organizational structure (this can be extended individually). If an administrator role grants administrative privileges that do not apply to the respective administrative scope, those privileges are ignored. For example, if an administrator role grants the Create Domain privilege but is assigned to an organizational unit administrator, this privilege has no effect.

Moving an administrative account within the organizational structure does not influence the assigned administrator roles.

Administrator roles and security considerations

Managing administrator roles and role assignment is protected by dedicated administrator privileges to restrict these operations to a small number of trusted administrators.

By default, administrators with the Assign Role or Revoke Role privilege, are permitted to assign or revoke only administrator roles that set the privileges that are currently assigned to their own account, respectively.

In contrast, the Create Role and Update Role privileges are very powerful, since they enable administrators to grant or remove privileges they don’t currently own themselves. The Update Role privilege in particular is very sensitive, as it allows administrators to update any administrator role, including those that are assigned to themselves. This can impose a security risk, as it allows accidental or intentional privilege escalation and bypasses the principle of least privilege.

We strongly recommend that administrator roles are created initially by a super administrator (for example, the first administrator), and that the Update Role privilege is granted only in exceptional circumstances to very trusted administrators, or preferably, to no one else.

Keep in mind that if you specify an upgrade administrator during a product upgrade from a version that does not support administrator roles to a version that does, the selected account is automatically granted all new administrative privileges, including the Create Role and Update Role privileges.

Best practices: Administrator roles

Clearly defined roles make it easier to understand who can perform which actions, simplify audits, and reduce the risk of accidental or unauthorized changes to the system.

  • Apply the principle of least privilege. Assign administrators only the roles they need to perform their tasks. Avoid granting broad or high‑privilege roles unless absolutely necessary.

  • Prefer roles over direct privilege assignments. Use administrator roles to manage administrative access whenever possible. Roles are easier to maintain, review, and audit than individually assigned privileges.

  • Use multiple roles instead of custom privilege sets. Combine existing administrator roles to match responsibilities rather than creating complex or highly specific configurations that cannot be reused to improve clarity and reduce maintenance effort.

  • Separate responsibilities across roles. Avoid assigning roles that combine unrelated or conflicting responsibilities. Separating duties improves security and accountability.

  • Review roles and role assignments regularly. Periodically review administrator roles and their assignments to ensure they still match current responsibilities, especially after organizational or personnel changes.

  • Use higher‑privilege roles sparingly. Reserve powerful roles for a small number of trusted administrators.