REST Access Controller (restServiceAccessController)
Description
The Access Controller plugin ensures that the logged-in administrator has permission to access the requested REST resources. The REST access controller can only allow additional access to REST resources, but not restrict it more than defined by the role based access rules below.
Attributes
Assignable plugins
List Users (listUsers)
Description
Roles required to list and search for users. At least one of the comma-separated roles are sufficient. Without a value, access is always denied. The special value 'NO RESTRICTION' (not combinable with any role names) allows access for any authenticated admin, without role restrictions.
Attributes
Suggested values
NO RESTRICTION, useradmin, helpdesk, useradmin,helpdesk, useradmin,tokenadmin, tokenadmin,helpdesk, useradmin,tokenadmin,helpdesk,sysadmin,superadmin
View User Details (viewUser)
Description
Roles required to view user details. At least one of the comma-separated roles are sufficient. Without a value, access is always denied. The special value 'NO RESTRICTION' (not combinable with any role names) allows access for any authenticated admin, without role restrictions.
Attributes
Suggested values
NO RESTRICTION, useradmin, helpdesk, useradmin,helpdesk, useradmin,tokenadmin, tokenadmin,helpdesk, useradmin,tokenadmin,helpdesk,sysadmin,superadmin
View User Logs (viewUserLogs)
Description
Roles required to view user related logs in the user details. At least one of the comma-separated roles are sufficient. Without a value, access is always denied. The special value 'NO RESTRICTION' (not combinable with any role names) allows access for any authenticated admin, without role restrictions.
Attributes
Suggested values
NO RESTRICTION, useradmin, helpdesk, useradmin,helpdesk, useradmin,tokenadmin, tokenadmin,helpdesk, useradmin,tokenadmin,helpdesk,superadmin
View User Context Data (viewContextData)
Description
Roles required to view user context data. At least one of the comma-separated roles are sufficient. Without a value, access is always denied. The special value 'NO RESTRICTION' (not combinable with any role names) allows access for any authenticated admin, without role restrictions.
Attributes
Suggested values
NO RESTRICTION, useradmin, helpdesk, useradmin,helpdesk, useradmin,tokenadmin, tokenadmin,helpdesk, useradmin,tokenadmin,helpdesk,sysadmin,superadmin
View User Context Data (fine-grained) (detailedViewContextData)
Description
Fine-grained access rules for context data fields view. Has precedence over 'View User Context Data'.
Attributes
Assignable plugins
Display User Management Extensions (displayUserManagementExtensions)
Description
Administrators with these roles that can see User Management Extensions.
The JavaScript file that contains the User Management Extensions always has the same accessibility as the rest of the Adminapp UI and can be accessed by unauthenticated users/administrators.
At least one of the comma-separated roles are sufficient. Without a value, access is always denied. The special value 'NO RESTRICTION' (not combinable with any role names) allows access for any authenticated admin, without role restrictions.
Attributes
Suggested values
NO RESTRICTION, useradmin, helpdesk, useradmin,helpdesk, useradmin,tokenadmin, tokenadmin,helpdesk, useradmin,tokenadmin,helpdesk,sysadmin,superadmin
Display User Management Extensions (fine-grained) (detailedDisplayUserManagementExtensions)
Description
Fine-grained display rules for User Management Extensions. Has precedence over 'Display User Management Extensions'.
This setting does not influence the delivered JavaScript for the User Management Extension. It will always contain the code for all User Management Extensions.
Attributes
Assignable plugins
Edit User Details (editUser)
Description
Roles required to edit user details. At least one of the comma-separated roles are sufficient. Without a value, access is always denied. The special value 'NO RESTRICTION' (not combinable with any role names) allows access for any authenticated admin, without role restrictions.
Attributes
Suggested values
NO RESTRICTION, useradmin, helpdesk, useradmin,helpdesk, useradmin,tokenadmin, tokenadmin,helpdesk, useradmin,tokenadmin,helpdesk,sysadmin,superadmin
Edit User Context Data (fine-grained) (detailedEditContextData)
Description
Fine-grained access rules for context data fields editing. 'Edit User Details' has precedence over these access rules.
Attributes
Assignable plugins
Edit Username (editUsername)
Description
Roles required to edit the user name. At least one of the comma-separated roles are sufficient. Without a value, access is always denied. The special value 'NO RESTRICTION' (not combinable with any role names) allows access for any authenticated admin, without role restrictions.
Attributes
Suggested values
NO RESTRICTION, useradmin, helpdesk, useradmin,helpdesk, useradmin,tokenadmin, tokenadmin,helpdesk, useradmin,tokenadmin,helpdesk,sysadmin,superadmin
Delete User (deleteUser)
Description
Roles required to delete a user. At least one of the comma-separated roles are sufficient. Without a value, access is always denied. The special value 'NO RESTRICTION' (not combinable with any role names) allows access for any authenticated admin, without role restrictions.
Attributes
Suggested values
NO RESTRICTION, useradmin, helpdesk, useradmin,helpdesk, useradmin,tokenadmin, tokenadmin,helpdesk, useradmin,tokenadmin,helpdesk,sysadmin,superadmin
Add New User (createUser)
Description
Roles required to add users. At least one of the comma-separated roles are sufficient. Without a value, access is always denied. The special value 'NO RESTRICTION' (not combinable with any role names) allows access for any authenticated admin, without role restrictions.
Attributes
Suggested values
NO RESTRICTION, useradmin, helpdesk, useradmin,helpdesk, useradmin,tokenadmin, tokenadmin,helpdesk, useradmin,tokenadmin,helpdesk,sysadmin,superadmin
Lock User (lockUser)
Description
Roles required to lock a user. At least one of the comma-separated roles are sufficient. Without a value, access is always denied. The special value 'NO RESTRICTION' (not combinable with any role names) allows access for any authenticated admin, without role restrictions.
Attributes
Suggested values
NO RESTRICTION, useradmin, helpdesk, useradmin,helpdesk, useradmin,tokenadmin, tokenadmin,helpdesk, useradmin,tokenadmin,helpdesk,sysadmin,superadmin
Unlock User (unlockUser)
Description
Roles required to unlock a user. At least one of the comma-separated roles are sufficient. Without a value, access is always denied. The special value 'NO RESTRICTION' (not combinable with any role names) allows access for any authenticated admin, without role restrictions.
Attributes
Suggested values
NO RESTRICTION, useradmin, helpdesk, useradmin,helpdesk, useradmin,tokenadmin, tokenadmin,helpdesk, useradmin,tokenadmin,helpdesk,sysadmin,superadmin
Manage OAuth 2.0 User Consents (manageOAuth2Consents)
Description
Roles required to manage OAuth 2.0 consents for a user. If granted, takes precedence over "Edit User Details". At least one of the comma-separated roles are sufficient. Without a value, access is always denied. The special value 'NO RESTRICTION' (not combinable with any role names) allows access for any authenticated admin, without role restrictions.
Attributes
Suggested values
NO RESTRICTION, useradmin, helpdesk, useradmin,helpdesk, useradmin,tokenadmin, tokenadmin,helpdesk, useradmin,tokenadmin,helpdesk,sysadmin,superadmin
Order Password Letter (orderPassword)
Description
Roles required to order a password letter. At least one of the comma-separated roles are sufficient. Without a value, access is always denied. The special value 'NO RESTRICTION' (not combinable with any role names) allows access for any authenticated admin, without role restrictions.
Attributes
Suggested values
NO RESTRICTION, useradmin, helpdesk, useradmin,helpdesk, useradmin,tokenadmin, tokenadmin,helpdesk, useradmin,tokenadmin,helpdesk,sysadmin,superadmin
Cancel Password Letter Order (unorderPassword)
Description
Roles required to cancel an order for a password letter. At least one of the comma-separated roles are sufficient. Without a value, access is always denied. The special value 'NO RESTRICTION' (not combinable with any role names) allows access for any authenticated admin, without role restrictions.
Attributes
Suggested values
NO RESTRICTION, useradmin, helpdesk, useradmin,helpdesk, useradmin,tokenadmin, tokenadmin,helpdesk, useradmin,tokenadmin,helpdesk,sysadmin,superadmin
Delete User Password (deletePassword)
Description
Roles required to delete a user's password. At least one of the comma-separated roles are sufficient. Without a value, access is always denied. The special value 'NO RESTRICTION' (not combinable with any role names) allows access for any authenticated admin, without role restrictions.
Attributes
Suggested values
NO RESTRICTION, useradmin, helpdesk, useradmin,helpdesk, useradmin,tokenadmin, tokenadmin,helpdesk, useradmin,tokenadmin,helpdesk,sysadmin,superadmin
Generate Or Set User Password (generatePassword)
Description
Roles required to generate or set a user's password. At least one of the comma-separated roles are sufficient. Without a value, access is always denied. The special value 'NO RESTRICTION' (not combinable with any role names) allows access for any authenticated admin, without role restrictions.
Attributes
Suggested values
NO RESTRICTION, useradmin, helpdesk, useradmin,helpdesk, useradmin,tokenadmin, tokenadmin,helpdesk, useradmin,tokenadmin,helpdesk,sysadmin,superadmin
Trigger Password Reset (triggerPasswordReset)
Description
Roles required to trigger a password reset. At least one of the comma-separated roles are sufficient. Without a value, access is always denied. The special value 'NO RESTRICTION' (not combinable with any role names) allows access for any authenticated admin, without role restrictions.
Attributes
Suggested values
NO RESTRICTION, useradmin, helpdesk, useradmin,helpdesk, useradmin,tokenadmin, tokenadmin,helpdesk, useradmin,tokenadmin,helpdesk,sysadmin,superadmin
View Authentication Token (viewToken)
Description
Roles required to view token details on users or in the token manager. At least one of the comma-separated roles are sufficient. Without a value, access is always denied. The special value 'NO RESTRICTION' (not combinable with any role names) allows access for any authenticated admin, without role restrictions.
Attributes
Suggested values
NO RESTRICTION, useradmin, helpdesk, useradmin,helpdesk, useradmin,tokenadmin, tokenadmin,helpdesk, useradmin,tokenadmin,helpdesk,sysadmin,superadmin
Edit Authentication Token (editToken)
Description
Roles required to edit a token. At least one of the comma-separated roles are sufficient. Without a value, access is always denied. The special value 'NO RESTRICTION' (not combinable with any role names) allows access for any authenticated admin, without role restrictions.
Attributes
Suggested values
NO RESTRICTION, useradmin, helpdesk, useradmin,helpdesk, useradmin,tokenadmin, tokenadmin,helpdesk, useradmin,tokenadmin,helpdesk,sysadmin,superadmin
Order New Authentication Token (orderNewToken)
Description
Roles required to order a new token. At least one of the comma-separated roles are sufficient. Without a value, access is always denied. The special value 'NO RESTRICTION' (not combinable with any role names) allows access for any authenticated admin, without role restrictions.
Attributes
Suggested values
NO RESTRICTION, useradmin, helpdesk, useradmin,helpdesk, useradmin,tokenadmin, tokenadmin,helpdesk, useradmin,tokenadmin,helpdesk,sysadmin,superadmin
Cancel Authentication Token Order (unorderNewToken)
Description
Roles required to cancel a token order. At least one of the comma-separated roles are sufficient. Without a value, access is always denied. The special value 'NO RESTRICTION' (not combinable with any role names) allows access for any authenticated admin, without role restrictions.
Attributes
Suggested values
NO RESTRICTION, useradmin, helpdesk, useradmin,helpdesk, useradmin,tokenadmin, tokenadmin,helpdesk, useradmin,tokenadmin,helpdesk,sysadmin,superadmin
Delete Authentication Token (deleteToken)
Description
Roles required to delete a token. At least one of the comma-separated roles are sufficient. Without a value, access is always denied. The special value 'NO RESTRICTION' (not combinable with any role names) allows access for any authenticated admin, without role restrictions.
Attributes
Suggested values
NO RESTRICTION, useradmin, helpdesk, useradmin,helpdesk, useradmin,tokenadmin, tokenadmin,helpdesk, useradmin,tokenadmin,helpdesk,sysadmin,superadmin
Activate Authentication Token (activateToken)
Description
Roles required to activate a token. At least one of the comma-separated roles are sufficient. Without a value, access is always denied. The special value 'NO RESTRICTION' (not combinable with any role names) allows access for any authenticated admin, without role restrictions.
Attributes
Suggested values
NO RESTRICTION, useradmin, helpdesk, useradmin,helpdesk, useradmin,tokenadmin, tokenadmin,helpdesk, useradmin,tokenadmin,helpdesk,sysadmin,superadmin
Deactivate Authentication Token (deactivateToken)
Description
Roles required to deactivate a token. At least one of the comma-separated roles are sufficient. Without a value, access is always denied. The special value 'NO RESTRICTION' (not combinable with any role names) allows access for any authenticated admin, without role restrictions.
Attributes
Suggested values
NO RESTRICTION, useradmin, helpdesk, useradmin,helpdesk, useradmin,tokenadmin, tokenadmin,helpdesk, useradmin,tokenadmin,helpdesk,sysadmin,superadmin
Generate Token Activation Key IAK (generateTokenIak)
Description
Roles required to generate an IAK activation key. At least one of the comma-separated roles are sufficient. Without a value, access is always denied. The special value 'NO RESTRICTION' (not combinable with any role names) allows access for any authenticated admin, without role restrictions.
Attributes
Suggested values
NO RESTRICTION, useradmin, helpdesk, useradmin,helpdesk, useradmin,tokenadmin, tokenadmin,helpdesk, useradmin,tokenadmin,helpdesk,sysadmin,superadmin
Token Management (manageTokens)
Description
Roles required to manage (import) tokens. At least one of the comma-separated roles are sufficient. Without a value, access is always denied. The special value 'NO RESTRICTION' (not combinable with any role names) allows access for any authenticated admin, without role restrictions.
Attributes
Suggested values
NO RESTRICTION, useradmin, helpdesk, useradmin,helpdesk, useradmin,tokenadmin, tokenadmin,helpdesk, useradmin,tokenadmin,helpdesk,sysadmin,superadmin
View OATH OTP Token Secret (viewOathOtpTokenSecret)
Description
Roles required to view the shared secret of OATH OTP tokens. At least one of the listed, comma-separated roles are sufficient. No value means not allowed for anyone. 'NO RESTRICTION' allows access to everyone.
Attributes
Suggested values
NO RESTRICTION, useradmin, helpdesk, useradmin,helpdesk, useradmin,tokenadmin, tokenadmin,helpdesk, useradmin,tokenadmin,helpdesk,sysadmin,superadmin
View Airlock 2FA Activation Secret (viewAirlock2FAActivationSecret)
Description
Roles required to view the Airlock 2FA activation code(s), e.g. when creating or fetching Airlock 2FA activation letters. At least one of the listed, comma-separated roles are sufficient. No value means not allowed for anyone. 'NO RESTRICTION' allows access to everyone.
Attributes
Suggested values
NO RESTRICTION, useradmin, helpdesk, useradmin,helpdesk, useradmin,tokenadmin, tokenadmin,helpdesk, useradmin,tokenadmin,helpdesk,sysadmin,superadmin
View Cronto Activation Secret (viewCrontoActivationSecret)
Description
Roles required to view the Cronto activation code(s). At least one of the listed, comma-separated roles are sufficient. No value means not allowed for anyone. 'NO RESTRICTION' allows access to everyone.
Attributes
Suggested values
NO RESTRICTION, useradmin, helpdesk, useradmin,helpdesk, useradmin,tokenadmin, tokenadmin,helpdesk, useradmin,tokenadmin,helpdesk,sysadmin,superadmin
View Technical Clients (viewTechnicalClients)
Description
Roles required to view technical clients (list with details). At least one of the comma-separated roles are sufficient. Without a value, access is always denied. The special value 'NO RESTRICTION' (not combinable with any role names) allows access for any authenticated admin, without role restrictions.
Attributes
Suggested values
NO RESTRICTION, useradmin, helpdesk, useradmin,helpdesk, useradmin,tokenadmin, tokenadmin,helpdesk, useradmin,tokenadmin,helpdesk,sysadmin,superadmin
Create And Edit Technical Clients / API Keys / Plans (createEditTechnicalClient)
Description
Roles required to create and edit technical clients, its API keys and plans. Also allows to delete API keys and plans. At least one of the comma-separated roles are sufficient. Without a value, access is always denied. The special value 'NO RESTRICTION' (not combinable with any role names) allows access for any authenticated admin, without role restrictions.
Attributes
Suggested values
NO RESTRICTION, useradmin, helpdesk, useradmin,helpdesk, useradmin,tokenadmin, tokenadmin,helpdesk, useradmin,tokenadmin,helpdesk,sysadmin,superadmin
Delete Technical Clients (deleteTechnicalClient)
Description
Roles required to delete technical clients. At least one of the comma-separated roles are sufficient. Without a value, access is always denied. The special value 'NO RESTRICTION' (not combinable with any role names) allows access for any authenticated admin, without role restrictions.
Attributes
Suggested values
NO RESTRICTION, useradmin, helpdesk, useradmin,helpdesk, useradmin,tokenadmin, tokenadmin,helpdesk, useradmin,tokenadmin,helpdesk,sysadmin,superadmin
Lock Technical Clients / API Keys (lockTechnicalClient)
Description
Roles required to lock technical clients and API keys. At least one of the comma-separated roles are sufficient. Without a value, access is always denied. The special value 'NO RESTRICTION' (not combinable with any role names) allows access for any authenticated admin, without role restrictions.
Attributes
Suggested values
NO RESTRICTION, useradmin, helpdesk, useradmin,helpdesk, useradmin,tokenadmin, tokenadmin,helpdesk, useradmin,tokenadmin,helpdesk,sysadmin,superadmin
Unlock Technical Clients / API Keys (unlockTechnicalClient)
Description
Roles required to unlock technical clients and API keys. At least one of the comma-separated roles are sufficient. Without a value, access is always denied. The special value 'NO RESTRICTION' (not combinable with any role names) allows access for any authenticated admin, without role restrictions.
Attributes
Suggested values
NO RESTRICTION, useradmin, helpdesk, useradmin,helpdesk, useradmin,tokenadmin, tokenadmin,helpdesk, useradmin,tokenadmin,helpdesk,sysadmin,superadmin
List Maintenance Messages (listMaintenanceMessages)
Description
Roles required to list maintenance messages. At least one of the comma-separated roles are sufficient. Without a value, access is always denied. The special value 'NO RESTRICTION' (not combinable with any role names) allows access for any authenticated admin, without role restrictions.
Attributes
Suggested values
NO RESTRICTION, useradmin, helpdesk, useradmin,helpdesk, useradmin,tokenadmin, tokenadmin,helpdesk, useradmin,tokenadmin,helpdesk,sysadmin,superadmin
Edit Maintenance Messages (editMaintenanceMessage)
Description
Roles required to edit maintenance messages. At least one of the comma-separated roles are sufficient. Without a value, access is always denied. The special value 'NO RESTRICTION' (not combinable with any role names) allows access for any authenticated admin, without role restrictions.
Attributes
Suggested values
NO RESTRICTION, useradmin, helpdesk, useradmin,helpdesk, useradmin,tokenadmin, tokenadmin,helpdesk, useradmin,tokenadmin,helpdesk,sysadmin,superadmin
Delete Maintenance Messages (deleteMaintenanceMessage)
Description
Roles required to delete maintenance messages. At least one of the comma-separated roles are sufficient. Without a value, access is always denied. The special value 'NO RESTRICTION' (not combinable with any role names) allows access for any authenticated admin, without role restrictions.
Attributes
Suggested values
NO RESTRICTION, useradmin, helpdesk, useradmin,helpdesk, useradmin,tokenadmin, tokenadmin,helpdesk, useradmin,tokenadmin,helpdesk,sysadmin,superadmin
List Administrators (listAdministrators)
Description
Roles required to list administrators. At least one of the comma-separated roles are sufficient. Without a value, access is always denied. The special value 'NO RESTRICTION' (not combinable with any role names) allows access for any authenticated admin, without role restrictions.
Attributes
Suggested values
NO RESTRICTION, useradmin, helpdesk, useradmin,helpdesk, useradmin,tokenadmin, tokenadmin,helpdesk, useradmin,tokenadmin,helpdesk,sysadmin,superadmin
View Administrators (viewAdministrator)
Description
Roles required to view administrator details. At least one of the comma-separated roles are sufficient. Without a value, access is always denied. The special value 'NO RESTRICTION' (not combinable with any role names) allows access for any authenticated admin, without role restrictions.
Attributes
Suggested values
NO RESTRICTION, useradmin, helpdesk, useradmin,helpdesk, useradmin,tokenadmin, tokenadmin,helpdesk, useradmin,tokenadmin,helpdesk,sysadmin,superadmin
Edit Administrators (editAdministrator)
Description
Roles required to edit administrators. At least one of the comma-separated roles are sufficient. Without a value, access is always denied. The special value 'NO RESTRICTION' (not combinable with any role names) allows access for any authenticated admin, without role restrictions.
CAUTION: Editing administrators includes assigning roles to administrators. Thus, an administrator with this privilege is able to assign this privilege also to other administrators.
Attributes
Suggested values
NO RESTRICTION, useradmin, helpdesk, useradmin,helpdesk, useradmin,tokenadmin, tokenadmin,helpdesk, useradmin,tokenadmin,helpdesk,sysadmin,superadmin
Delete Administrators (deleteAdministrator)
Description
Roles required to delete administrators. At least one of the comma-separated roles are sufficient. Without a value, access is always denied. The special value 'NO RESTRICTION' (not combinable with any role names) allows access for any authenticated admin, without role restrictions.
Attributes
Suggested values
NO RESTRICTION, useradmin, helpdesk, useradmin,helpdesk, useradmin,tokenadmin, tokenadmin,helpdesk, useradmin,tokenadmin,helpdesk,sysadmin,superadmin
Add New Administrators (createAdministrator)
Description
Roles required to create administrators. At least one of the comma-separated roles are sufficient. Without a value, access is always denied. The special value 'NO RESTRICTION' (not combinable with any role names) allows access for any authenticated admin, without role restrictions.
Attributes
Suggested values
NO RESTRICTION, useradmin, helpdesk, useradmin,helpdesk, useradmin,tokenadmin, tokenadmin,helpdesk, useradmin,tokenadmin,helpdesk,sysadmin,superadmin
Lock Administrators (lockAdministrator)
Description
Roles required to lock administrators. At least one of the comma-separated roles are sufficient. Without a value, access is always denied. The special value 'NO RESTRICTION' (not combinable with any role names) allows access for any authenticated admin, without role restrictions.
Attributes
Suggested values
NO RESTRICTION, useradmin, helpdesk, useradmin,helpdesk, useradmin,tokenadmin, tokenadmin,helpdesk, useradmin,tokenadmin,helpdesk,sysadmin,superadmin
Unlock Administrators (unlockAdministrator)
Description
Roles required to unlock administrators. At least one of the comma-separated roles are sufficient. Without a value, access is always denied. The special value 'NO RESTRICTION' (not combinable with any role names) allows access for any authenticated admin, without role restrictions.
Attributes
Suggested values
NO RESTRICTION, useradmin, helpdesk, useradmin,helpdesk, useradmin,tokenadmin, tokenadmin,helpdesk, useradmin,tokenadmin,helpdesk,sysadmin,superadmin
Delete Administrator's Password (deleteAdministratorPassword)
Description
Roles required to delete administrators password. At least one of the comma-separated roles are sufficient. Without a value, access is always denied. The special value 'NO RESTRICTION' (not combinable with any role names) allows access for any authenticated admin, without role restrictions.
Attributes
Suggested values
NO RESTRICTION, useradmin, helpdesk, useradmin,helpdesk, useradmin,tokenadmin, tokenadmin,helpdesk, useradmin,tokenadmin,helpdesk,sysadmin,superadmin
Change Administrator's Password (changeAdministratorPassword)
Description
Roles required for an administrator to change his own password. At least one of the comma-separated roles are sufficient. Without a value, access is always denied. The special value 'NO RESTRICTION' (not combinable with any role names) allows access for any authenticated admin, without role restrictions.
Attributes
Suggested values
NO RESTRICTION, useradmin, helpdesk, useradmin,helpdesk, useradmin,tokenadmin, tokenadmin,helpdesk, useradmin,tokenadmin,helpdesk,sysadmin,superadmin
Generate Administrator Password (generateAdministratorPassword)
Description
Roles required to generate administrators password. At least one of the comma-separated roles are sufficient. Without a value, access is always denied. The special value 'NO RESTRICTION' (not combinable with any role names) allows access for any authenticated admin, without role restrictions.
Attributes
Suggested values
NO RESTRICTION, useradmin, helpdesk, useradmin,helpdesk, useradmin,tokenadmin, tokenadmin,helpdesk, useradmin,tokenadmin,helpdesk,sysadmin,superadmin
Edit Configuration (editConfig)
Description
Roles required to edit configurations. At least one of the comma-separated roles are sufficient. Without a value, access is always denied. The special value 'NO RESTRICTION' (not combinable with any role names) allows access for any authenticated admin, without role restrictions.
Attributes
Suggested values
NO RESTRICTION, useradmin, helpdesk, useradmin,helpdesk, useradmin,tokenadmin, tokenadmin,helpdesk, useradmin,tokenadmin,helpdesk,sysadmin,superadmin
Apply Configuration (applyConfig)
Description
Roles required to apply configurations. At least one of the comma-separated roles are sufficient. Without a value, access is always denied. The special value 'NO RESTRICTION' (not combinable with any role names) allows access for any authenticated admin, without role restrictions.
CAUTION: Because administrator access control is also part of the configuration, an administrator with this privilege can possibly gain all possible administrator rights.
Attributes
Suggested values
NO RESTRICTION, useradmin, helpdesk, useradmin,helpdesk, useradmin,tokenadmin, tokenadmin,helpdesk, useradmin,tokenadmin,helpdesk,sysadmin,superadmin
View Log Files (viewLog)
Description
Roles required to view log files. At least one of the comma-separated roles are sufficient. Without a value, access is always denied. The special value 'NO RESTRICTION' (not combinable with any role names) allows access for any authenticated admin, without role restrictions.
Attributes
Suggested values
NO RESTRICTION, useradmin, helpdesk, useradmin,helpdesk, useradmin,tokenadmin, tokenadmin,helpdesk, useradmin,tokenadmin,helpdesk,sysadmin,superadmin
View License (viewLicense)
Description
Roles required to view and edit the license. At least one of the comma-separated roles are sufficient. Without a value, access is always denied. The special value 'NO RESTRICTION' (not combinable with any role names) allows access for any authenticated admin, without role restrictions.
Attributes
Suggested values
NO RESTRICTION, useradmin, helpdesk, useradmin,helpdesk, useradmin,tokenadmin, tokenadmin,helpdesk, useradmin,tokenadmin,helpdesk,sysadmin,superadmin
Access Service Container Management (accessServiceContainer)
Description
Roles required to access the service container. At least one of the comma-separated roles are sufficient. Without a value, access is always denied. The special value 'NO RESTRICTION' (not combinable with any role names) allows access for any authenticated admin, without role restrictions.
Attributes
Suggested values
NO RESTRICTION, useradmin, helpdesk, useradmin,helpdesk, useradmin,tokenadmin, tokenadmin,helpdesk, useradmin,tokenadmin,helpdesk,sysadmin,superadmin