Change the Scope of an Administrative Role
The scope of an administrative role determines which security domains and identity sources an administrator can manage. You can only modify the scope of a role that has the same or narrower scope as the role assigned to you.
If you change the scope, so that it does not include the entire deployment and only includes lower-level security domains, when you assign permissions to the role, you cannot grant any system-level permissions to the role, such as logging configuration. You cannot edit the Super Admin role.
Procedure
In the Security Console, click Administration > Administrative Roles > Manage Existing.
Click the administrative role that you want to edit, and select Edit.
In the Security Domain Scope tree, select the security domains in which the new role grants permissions.
The security domain scope determines where an administrator assigned this role has administrative permissions. When a role grants permissions in a security domain, permissions are also granted in each of its lower-level security domains in the security domain hierarchy.
In the Identity Source Scope field, select the identity sources where you want this role to grant permissions.
Click Saveand Finish.
Related Articles
Assign an Administrative Role 45Number of Views Administrative Role Scope and Permissions 36Number of Views Add an Administrative Role 25Number of Views Edit an Administrative Role 9Number of Views Unassign an Administrative Role 5Number of Views
Trending Articles
Change Requests stuck in the AFX Fulfillment Handler Workflow Node and Workflows Stalled in RSA Identity Governance & Life… Collector Stuck in Data Collection Phase with "Sent Request to Agent Hosting the Collector" RSA Authentication Manager 8.9 Patches and Hotfixes Readme How to manipulate imported RSA SecurID Software Token(s) on an iPhone or iPad device Workflows stuck in AFX fulfillment and/or Provisioning nodes in RSA Identity Governance & Lifecycle