Skip to main content

FAQ: Custom Admin Roles and Operations (Preview)

FAQ: Custom Admin Roles​

Can permissions from a pre-defined role be used as a baseline and modified during creation?

Yes. Admins can modify permissions based on the selected pre-defined role during first-time creation.

What if a custom role’s scope permissions exactly match a pre-defined JumpCloud role?

The Enterprise Portal will display an error and prevent the role from saving.

What are the role assignment rules?

An Admin can have only one role assigned (custom or pre-defined). A single custom role can be assigned to multiple Admins. You can’t assign multiple custom roles to the same Admin.

Are actions logged with Custom Roles?

Yes. Create/edit/delete custom roles will be logged along with existing Admin role change events. Insight events are also logged for custom role actions.

Will Admins be notified when assigned a custom role?

Yes. When an Admin with billing creates a new Admin and assigns a custom role (either from an existing user or as a new admin), the new Admin will receive an email using the current standard role assignment template.

What happens if the custom role is linked to an Admin?

The Enterprise Portal will notify the Admin that the role is linked to an existing Admin and provide the option to select an alternate role from the list of pre-defined and available custom roles.

Will there be new audit log events for custom roles?

Yes. Additional events will capture create, edit, and delete actions for custom role workflows.

What happens when a role not linked to any admin is deleted?

The role can be deleted immediately without additional prompts.

What happens when deleting a role linked to one or more Admins?

The Enterprise Portal will display the number of linked Admins, and require the Admin to enter the number of linked Admins in a text box to confirm deletion, or cancel.

If an Admin has “No Access” for the User Management scope but “Edit” permission for the User Support scope, can they still unlock a user account?

No. The Admin will not be able to perform user support operations, including unlocking a user account.

Operational FAQs: Custom Admin Roles​

Why is the Users tab not visible under User Management for my Administrators?

The Users tab is hidden by design if a custom role has No Access permission for User Management scope.

If I give no access permission for User Management and Group management scope, what will the assigned Admins see?

If you remove both User Management and Group Management permissions from an admin role, the User Management tab from the left navigation bar will be hidden from any Admin who has been assigned that role.

If I give No Access permission for Core Administration and Administrator Management Scope, what will the assigned Admins see?

If you revoke all Administrator Management permissions from an admin role, the Settings page will be completely hidden from the left navigation bar for any Admin who has been assigned that role.

What permissions are needed for me to launch a Remote Assist session?

You need to have Edit permission for Remote Assist and Remote Assist Sessions scope having a minimum of No access permission to launch a Remote Assist session.

What permissions are needed for a role to perform delete operation using command?

In Order to perform delete operation using a command, you need Edit permission for Commands and Command Templates scopes.

What scopes control the access to Device Management certificate in conditional access policies?

The Device management certificate under Conditional Access Policies > Settings can be accessed based on the Organization Management scope permissions and it doesn’t depend on the Multi-Factor Authentication scope.

What roles are necessary for having access to the full set of billing permissions?

The Read Only permission for Subscription Information scope is dependent on Billing Management scope. Admins are expected to provide access of both these scopes for the full set of billing permissions.

If an Admin has No Access for the User Management scope but Edit permission for the User Support scope, can they still unlock a user account?

No. The Admin will not be able to perform user support operations, including unlocking a user account.

What permissions are needed to access Push endpoints, SSH Keys and WebAuthn?

An Admin needs to have ‘Edit’ access to the User Management scope so they can access Push endpoints, SSH Keys and WebAuthn.

Was this information helpful?