Skip to main content

Admin roles and login security

Use reusable admin roles to grant the minimum access needed, and require secure sign-in for accounts that can access Management Cloud.

Create an admin role​

  1. Open Enterprise Settings → Admin Roles.
  2. Click Add new admin role.
  3. Enter a role name and description.
  4. Select at least one permission.
  5. Review the permission groups, including organisation, users, roles, devices, networks, enrolment images, and FydeSign.
  6. Click OK.

Create admin role

The built-in Super Admin role grants every permission and cannot be edited or deleted. Keep the number of Super Admins small.

Assign a role​

  1. Open Users.
  2. Find the administrator.
  3. Click Edit roles.
  4. Select the required reusable roles.
  5. Save and ask the administrator to sign in again.
  6. Verify both required access and denied access.

Require secure sign-in​

  1. Open Enterprise Settings → Login Security.
  2. Review the current policy and accepted methods.
  3. Prepare all administrators to set up a Passkey or Authenticator app.
  4. Enable Require secure sign-in.
  5. Click Save.

Login security

Use Open account security to manage the current account's methods. Before enforcing the policy, keep at least two tested administrator accounts and a documented recovery contact.

Access review​

Review quarterly and whenever responsibilities change:

  • Super Admin membership.
  • Custom role permissions.
  • Inactive or departed users.
  • Login Security status.
  • Whether emergency access still works.

What's next​