{"id":75893,"date":"2024-01-08T17:47:04","date_gmt":"2024-01-08T22:47:04","guid":{"rendered":"https:\/\/jumpcloud.com\/?post_type=support&p=75893"},"modified":"2024-11-20T03:34:03","modified_gmt":"2024-11-20T08:34:03","slug":"admin-portal-roles","status":"publish","type":"support","link":"https:\/\/jumpcloud.com\/support\/admin-portal-roles","title":{"rendered":"Admin Portal Roles"},"content":{"rendered":"\n
Admin Roles are part of the foundation of protecting your organization by restricting access to only the areas people need to perform their daily job duties. JumpCloud offers a variety of roles to help keep things organized and secure.<\/p>\n\n\n\n
To set these roles, see\u00a0Settings in the JumpCloud Admin Portal<\/a>.<\/p>\n\n\n\n <\/p><\/div> Note:<\/strong> Role based permissions apply to administrator actions both in product, and the API key of each administrator.<\/p><\/div><\/div><\/div>\n\n\n\n This role is considered a Super Admin. <\/p>\n\n\n\n <\/p><\/div> Important:<\/strong> Carefully consider who you give this level of access. Accounts with this role have all privileges and can:<\/p><\/div><\/div><\/div>\n\n\n\n <\/p><\/div> Important:<\/strong> Carefully consider who you give this level of access. <\/p><\/div><\/div><\/div>\n\n\n\n This role has all of the privileges of an Administrator With Billing except privileges to manage payments (Billing), administrators, or the Multi-Tenant Portal.<\/p>\n\n\n\n Accounts with this role can manage users, devices, and groups.<\/p>\n\n\n\n Accounts with this role can manage account payment methods.<\/p>\n\n\n\n Accounts with this role can only run commands they’re given access to. <\/p>\n\n\n\n Accounts with this role can access and view JumpCloud resources, submit support requests, and manage users in the following ways:<\/p>\n\n\n\n Accounts with this role can access the Account tab in the MTP, with Read Only permissions everywhere else. From the Account tab, Admins can review the Account Overview, review payment history, update mailing and billing information, and view the usage associated with the account. <\/p>\n\n\n\n Accounts with this role have read-only permissions; they can access and view users and other JumpCloud resources, but can’t perform any management tasks.<\/p>\n\n\n\n When you apply roles with limited permissions, a banner is shown in the Admin Portal that explains the level of permissions the account has. <\/p>\n\n\n\n The following table outlines role permission scope for new and legacy roles. <\/p>\n\n\n\n Administrators:<\/p>\n Billing:<\/p>\n Billing payment information, including:<\/p>\n Multi-Tenant Portal:<\/p>\n Organization & User Portal:<\/p>\n Authentication:<\/p>\n Users:<\/p>\n Edit*<\/p>\n <\/p>\n <\/p>\n *Read Only for direct assignments to resources<\/p><\/div> <\/td>\n Groups:<\/p>\n Devices:<\/p>\n Directory & App User Management:<\/p>\n In-Product Support:<\/p>\n Case Portal:<\/p>\n Actions relating to submitted tickets and feature requests, including:<\/p>\n Notifications in the Admin Portal:<\/p>\n Insights:<\/p>\n Actions in Directory Insights and System Insights, including:<\/p>\n Commands:<\/p>\n Bulk User Imports:<\/p>\n SSO Applications:<\/p>\n RADIUS servers:<\/p>\n Remote Assist:<\/p>\n SaaS Management:<\/p>\n Admin Roles are part of the foundation of protecting your organization by restricting access to only the areas people need […]<\/p>\n","protected":false},"author":207,"featured_media":0,"template":"","meta":{"_acf_changed":false,"_oasis_is_in_workflow":0,"_oasis_original":0,"_oasis_task_priority":"","inline_featured_image":false,"footnotes":""},"support_category":[2848,2934],"support_tag":[],"coauthors":[2843],"acf":[],"yoast_head":"\nAdministrator With Billing<\/strong><\/h2>\n\n\n\n
\n
Administrator<\/strong><\/h2>\n\n\n\n
Manager<\/strong> <\/h2>\n\n\n\n
Command Runner With Billing<\/strong><\/h2>\n\n\n\n
Command Runner<\/strong><\/h2>\n\n\n\n
Help Desk<\/strong><\/h2>\n\n\n\n
\n
Billing Only<\/strong> <\/h2>\n\n\n\n
Read Only<\/strong><\/h2>\n\n\n\n
Admin Portal Roles<\/h3>\n
\n\n
\n \n <\/td>\n \n Admin Role <\/td>\n \n <\/td>\n \n <\/td>\n \n <\/td>\n \n <\/td>\n \n <\/td>\n \n <\/td>\n \n <\/td>\n <\/tr>\n \n \n Scope <\/td>\n \n Administrator with Billing <\/td>\n \n Administrator <\/td>\n \n Manager <\/td>\n \n Command Runner with Billing <\/td>\n \n Command Runner <\/td>\n \n Help Desk <\/td>\n \n Read Only <\/td>\n \n Billing Only <\/td>\n <\/tr>\n \n \n \n
\n Edit <\/td>\n \n Read Only <\/td>\n \n Read Only <\/td>\n \n No Access <\/td>\n \n No Access <\/td>\n \n Read Only <\/td>\n \n Read Only <\/td>\n \n No Access <\/td>\n <\/tr>\n \n \n \n
\n Edit <\/td>\n \n No Access <\/td>\n \n No Access <\/td>\n \n Edit <\/td>\n \n No Access <\/td>\n \n No Access <\/td>\n \n No Access <\/td>\n \n Edit <\/td>\n <\/tr>\n \n \n \n
\n Edit <\/td>\n \n Read Only <\/td>\n \n Read Only <\/td>\n \n N\/A <\/td>\n \n N\/A <\/td>\n \n Read Only <\/td>\n \n Read Only <\/td>\n \n No Access <\/td>\n <\/tr>\n \n \n \n
\n Edit <\/td>\n \n Edit <\/td>\n \n Read Only <\/td>\n \n No Access <\/td>\n \n No Access <\/td>\n \n Read Only <\/td>\n \n Read Only <\/td>\n \n No Access <\/td>\n <\/tr>\n \n \n \n
\n Edit <\/td>\n \n Edit <\/td>\n \n Read Only <\/td>\n \n No Access <\/td>\n \n No Access <\/td>\n \n Read Only <\/td>\n \n Read Only <\/td>\n \n No Access <\/td>\n <\/tr>\n \n \n \n
\n Edit <\/td>\n \n Edit <\/td>\n \n Edit <\/td>\n \n No Access <\/td>\n \n No Access <\/td>\n \n \n Read Only <\/td>\n \n No Access <\/td>\n <\/tr>\n \n \n \n
\n Edit <\/td>\n \n Edit <\/td>\n \n Edit <\/td>\n \n No Access <\/td>\n \n No Access <\/td>\n \n Read Only <\/td>\n \n Read Only <\/td>\n \n No Access <\/td>\n <\/tr>\n \n \n \n
\n Edit <\/td>\n \n Edit <\/td>\n \n Edit <\/td>\n \n No Access <\/td>\n \n No Access <\/td>\n \n Read Only <\/td>\n \n Read Only <\/td>\n \n No Access <\/td>\n <\/tr>\n \n \n \n
\n Edit <\/td>\n \n Edit <\/td>\n \n Read Only <\/td>\n \n No Access <\/td>\n \n No Access <\/td>\n \n Read Only <\/td>\n \n Read Only <\/td>\n \n No Access <\/td>\n <\/tr>\n \n \n \n
\n Edit <\/td>\n \n Edit <\/td>\n \n Edit <\/td>\n \n Edit <\/td>\n \n Edit <\/td>\n \n Edit <\/td>\n \n No Access <\/td>\n \n Edit <\/td>\n <\/tr>\n \n \n \n
\n Edit <\/td>\n \n Edit <\/td>\n \n Edit <\/td>\n \n Edit <\/td>\n \n Edit <\/td>\n \n Edit <\/td>\n \n Read Only <\/td>\n \n Edit <\/td>\n <\/tr>\n \n \n \n
\n Edit <\/td>\n \n Edit <\/td>\n \n Read Only <\/td>\n \n Read Only <\/td>\n \n Read Only <\/td>\n \n Read Only <\/td>\n \n Read Only <\/td>\n \n Read Only <\/td>\n <\/tr>\n \n \n \n
\n Edit <\/td>\n \n Edit <\/td>\n \n Edit <\/td>\n \n No Access <\/td>\n \n No Access <\/td>\n \n Edit <\/td>\n \n Edit <\/td>\n \n No Access <\/td>\n <\/tr>\n \n \n \n
\n Edit <\/td>\n \n Edit <\/td>\n \n Edit <\/td>\n \n Running & Scheduling access to Commands for assigned Commands <\/td>\n \n Running & Scheduling access to Commands for assigned Commands <\/td>\n \n Read Only <\/td>\n \n Read Only <\/td>\n \n No Access <\/td>\n <\/tr>\n \n \n \n
\n Edit <\/td>\n \n Edit <\/td>\n \n Edit <\/td>\n \n No Access <\/td>\n \n No Access\u00a0 <\/td>\n \n Edit <\/td>\n \n Read Only <\/td>\n \n No Access <\/td>\n <\/tr>\n \n \n \n
\n Edit <\/td>\n \n Edit <\/td>\n \n Read Only <\/td>\n \n No Access <\/td>\n \n No Access\u00a0 <\/td>\n \n Read Only <\/td>\n \n Read Only <\/td>\n \n No Access <\/td>\n <\/tr>\n \n \n \n
\n Edit <\/td>\n \n Edit <\/td>\n \n Read Only <\/td>\n \n No Access <\/td>\n \n No Access\u00a0 <\/td>\n \n Read Only <\/td>\n \n Read Only <\/td>\n \n No Access <\/td>\n <\/tr>\n \n \n \n
\n Edit <\/td>\n \n Edit <\/td>\n \n Edit <\/td>\n \n No Access <\/td>\n \n No Access\u00a0 <\/td>\n \n Launch Remote Assist (if Remote Assist is enabled in Settings) <\/td>\n \n No Access\u00a0 <\/td>\n \n No Access <\/td>\n <\/tr>\n \n \n \n
\n Edit <\/td>\n \n Edit <\/td>\n \n Edit <\/td>\n \n No Access <\/td>\n \n No Access\u00a0 <\/td>\n \n Read Only <\/td>\n \n Read Only <\/td>\n \n No Access <\/td>\n <\/tr>\n <\/table>\n<\/div><\/div>\n","protected":false},"excerpt":{"rendered":"