By default, EMM includes a set of roles. These default roles and permissions have been explained in the following subsections.
...
The following are the roles that are available by default in EMM:
administrator - Role assigned to the super tenant administrator by default.
Info If you are defining the permissions for an EMM administrator who needs to perform operations and configure policies, make sure to select admin-device-access. The admin-device-access permission allows the user to perform operations and configure policies for devices.
Expand title Click here fore more information on adding a new administrator role. If you wish to create a user with administrative permission other than the default administrator in EMM, follow the steps given below:
- Add a new a role.
- Configure role permissions by giving the respective user the permission for admin-device-access specifically.
Internal/everyone - This is a system reserved role to create system operations.
Info Roles with
internal/
depict the internal roles that are stored in the DB that is shipped with EMM. If you wish to prevent external operations being carried out by theInternal/everyone
role, revoke operations from the role.
Note |
---|
It must be noted that all roles starting with |
Permissions associated with user roles
...