Use these commands to manage administrative users instead of using the Admin Console. Administrative users must be added to the Admin tenant. To learn about the types of admin users, resources, and permissions, see Admin User Management.
You can assign the following permissions to an admin user with the add-user and set-permissions commands.
"super admin"
"admin"
Permissions JSON
Super Admins have full access to all resources. You cannot modify a Super Admin's permissions. By default, Admins can create and modify other Admins. They also have view access to all resources. You can modify an Admin's permissions.
To specify different permissions for each resource, use a Permissions JSON.
{
"resourceFieldName1": "permission1",
"resourceFieldName2": "permission2"
}The default Permissions JSON is shown below. You must enclose a Permissions JSON in single quotes, as shown, to assign it.
'{"um":"none","adaptiveRulesets":"read","detailReports":"read","userMgmt":"read","configuration":"read","authMetadataMgmt":"read"}'This Permissions JSON means the admin user cannot create or modify other admin users. They also have read access to the following:
Configuration for Adaptive Rulesets and their supporting objects
End user management
Configuration for the Authentication Server, API Server, and the Admin tenant
Authenticator metadata
The resource field names and their possible values are listed in the table below.
Resource | ResourceField | Permission Values |
|---|---|---|
Admin User Management | "um" | "admin", "super admin", "none" |
Configuration | "configuration" | "write","read","none" |
Dashboard | "dashboard" | "read","none" |
End User | "userMgmt" | "write","read","none" |
Metadata Management | "authMetadataMgmt" | "write","read","none" |
Rulesets | "adaptiveRulesets" | "write","read","none" |
Add-user
Syntax
./nnl-mgmt.sh admin add-user -tenantid <tenantid> -userid <userid> -firstname <first-name> -lastname <last-name> [-permission <"super admin" | "admin" | permission-json>]Parameter | Description |
|---|---|
userid | Mandatory. The admin user's unique ID. Used when they login to the Admin Console. |
tenantid | Mandatory. A tenant ID. Must be Admin. |
firstname | The admin user's first name |
lastname | The admin user's last name |
permission | Optional. Defaults to the default Permissions JSON, which means no access to Admin User Management and read access for all other resources. One of:
See Admin User Management Commands for details. |
Description
Creates a new administrative user in the Admin tenant. You can optionally assign permissions to the user.
The command returns a registration code. Send the userid and registration code to the new admin user. The new admin user must use the code to create their account as described in Admin User Management.
Examples
This example creates a Super Admin.
./nnl-mgmt.sh admin add-user -tenantid Admin -userid knaismith -firstname "Katherine" -lastname "Naismith" -permission "super admin"The example below creates an admin user who is a customer service representative.
They have access to the End User Management function and no other resources. You can also omit the resources that are assigned "none" from the Permissions JSON and get the same results.
./nnl-mgmt.sh admin add-user -tenantid Admin -userid jtsuji -firstname Jun -lastname Tsuji -permission '{"um":"none","dashboard":"none","detailReports":"none", "adaptiveRulesets":"none","configuration":"none", "authMetadataMgmt":"none","userMgmt":"write"}'The example below creates an admin user who can configure the Authentication Server, API Server, Admin tenant, and objects associated with Adaptive Authentication. They have no access to other resources.
./nnl-mgmt.sh admin add-user -tenantid Admin -userid vkola -firstname Vani -lastname Kola -permission '{"configuration":"write", "adaptiveRulesets":"write"}'Add-tenant-user
Syntax
./nnl-mgmt.sh admin add-tenant-user -tenantid <tenantid> -userid <userid> [‑copypermsfrom <from-tenantid>]Parameter | Description |
|---|---|
tenantid | Mandatory. A tenant ID. |
userid | Mandatory. An existing admin user's user ID. |
copypermsfrom | Optional. Defaults to the default Permissions JSON, which means no access to Admin User Management and read access for all other resources. A tenant ID that the user already belongs to. Copies the user's existing permissions from that tenant. See Admin User Management Commands for details. |
Description
Adds an existing administrative user to another tenant. You can optionally specify whether to copy their existing permissions from a tenant that they belong to.
Example
./nnl-mgmt.sh admin add-tenant-user -tenantid finance -userid knaismith ‑copypermsfrom marketingDelete-user
Syntax
./nnl-mgmt.sh admin delete-user -tenantid <tenantid> -userid <userid>Parameter | Description |
|---|---|
tenantid | Mandatory. The tenant ID. |
userid | Mandatory. The user ID of the admin user. |
Description
Deletes the admin user from the specified tenant.
Example
./nnl-mgmt.sh admin delete-user -tenantid finance -userid jtsujiGenerate-reg-code
Syntax
./nnl-mgmt.sh admin generate-reg-code -userid <userid>Parameter | Description |
|---|---|
userid | Mandatory. The admin user's unique ID. Used when they login to the Admin Console. |
Description
Generates a new registration code for the user. The code is good for 48 hours. Send the code and userid to the new admin user. The new admin user must use the code to create their account as described in Admin User Management.
Example
./nnl-mgmt.sh admin generate-reg-code -userid sshenoySet-permissions
Syntax
./nnl-mgmt.sh admin set-permissions -tenantid <tenantid> -userid <userid> [‑permission <'admin'|'super admin'|'{JSON-permission-string}'>]Parameter | Description |
|---|---|
tenantid | Mandatory. A tenant ID. |
userid | Mandatory. The admin user's unique ID. Used when they login to the Admin Console. |
permission | Optional. Defaults to the default Permissions JSON, which means no access to Admin User Management and read access for all other resources. One of:
See Admin User Management Commands for details. |
Description
Assigns the specified permissions to the admin user for the specified tenant. Only resources specifically listed in the Permissions JSON are updated. Resources that are not listed keep their current permissions.
Example
./nnl-mgmt.sh admin set-permissions -tenantid finance -userid jtsuji -permission '{"userMgmt":"write", "dashboard":"read"}'