icon-zslogin.svg
ZIdentity

Admin Roles and Permissions

ZIdentity provides a set of predefined roles and permissions that you can assign to users and groups. As an admin, you can control what objects and services users are entitled to access on the subscribed Zscaler services.

You can assign a single or multiple roles to users. When a user is assigned multiple roles, the permission levels are hierarchical and the effective level of each permission is the highest from the user’s set of roles. For example, if a user has two roles, and one role has an External Identities permission of Restrictive View and the other has an External Identities permission of View, the effective permission level is View.

ZIdentity ModulesPermissionDetails
Admin Sign on PolicyFull
  • View sign-on policy.
  • Edit all configurations in sign-on policy.

    Exception: If the admin does not have the permission for “IP Locations - Full” or “IP Locations - View”, they are not allowed to access sign-on policy.

View Only
  • View sign-on policy and rules.

    Exception: If the admin does not have the permission for “IP Locations - Full” or “IP Locations - View” they are not allowed to access sign-on policy.

NoneNot allowed to view the contents of sign-on policy.
Authentication MethodsFull
  • View password policy.
  • Edit all configuration on password policy.
  • Edit authentication methods.
View Only
  • View password policy.
  • View all configuration on password policy.
  • View authentication methods.
  • Not allowed to change any configuration value.
Users and GroupsFull
  • View users and user groups.
  • Add, edit, delete, activate, deactivate user.
  • Add, edit, delete group.
  • Import group details from a CSV file.
  • Change group name, assign users to group.
  • Add, edit, delete attribute.
View OnlyView users, user groups, user attributes, and group attributes.
NoneNot allowed to access users, user groups, user attributes, and group attributes.
User CredentialsFull
  • Access, view, and change security settings (all attributes and settings) only when admins have “Users and Groups - View” or “Users and Groups - Full” permissions.
  • Admins without the "Users and Groups -Full" permission cannot change a user's primary and secondary email address even though they are used as credentials..
View Only
  • View security settings (all attributes and settings) only when admins have “Users and Groups - View” or “Users and Groups - Full” permissions.
NoneNot allowed to access security settings.
RolesFull
  • View, add, edit, and delete roles.
  • Admins with “Users and Groups - Full or View” permission can add or edit roles.
View Only
  • View roles.
  • View all configuration for roles.
External IdentitiesFull
  • View external identities (both primary and secondary IdPs).
  • Add and edit primary and secondary IdPs.
  • Change all configuration per IdP.
View Only
  • View external identities (both primary and secondary IdPs).
  • View all configuration per IdP.

Restricted View

  • View external identities (both primary and secondary IdPs).
  • View configuration per IdP except for Provisioning > SCIM Provisioning > Bearer Token.
NoneNot allowed to access or view external identities.
IP Locations & GroupsFull
  • View IP locations and location groups.
  • Add location and location groups, import IP locations and location group details from a CSV file.
  • Edit, delete IP locations and IP location groups.
  • Change all configuration per IP location and IP location groups.
View OnlyView IP locations, IP location groups, configuration per location or location group.
NoneNot allowed to access IP locations or IP location groups.
Authentication SessionFull
  • View and change session timeout duration.
  • View and change authentication session for service enrollment.
  • View and change force authentication for private access reauthentication.
View Only
  • View session timeout duration.
  • View authentication session for service enrollment.
  • View force authentication for private access reauthentication.
Administrative EntitlementsFull
  • View and search administrative entitlements.
  • Access users and user groups.
  • Assign users, user groups.
  • Delete user assignments and user group assignments.
  • Admin with "Roles - Full" or "Roles - View Only" permission can assign roles
Restricted Full
  • Access, view, and search administrative entitlements.
  • Admin with “Users and Groups - Full” or “Users and Groups - View” permission can access the Users and User Groups tabs of individual tenants.
  • View all users and user groups assignments.
  • View the user list on the User Groups tab.
  • Admin with "Roles -Full" permission can assign roles.
  • Admin with "Roles -View Only" permission cannot assign roles.

If admin has permissions in individual tenants to administer administrators, they can:

  • Assign users and user groups.
  • Remove user assignments and user group assignments.
View Only
  • View administrative entitlements
  • View user and user group assignments
NoneNot allowed to access administrative entitlements
Service EntitlementsFull
  • View service entitlements
  • Assign users, user groups, delete user assignments and user group assignments
View Only
  • View service entitlements
  • View user and user group assignments
NoneNot allowed to access service entitlements
Audit LogsView OnlyView audit logs
NoneNot allowed to view audit logs
Guest DomainFull
  • Add guest domains
  • Edit guest domains
  • Delete guest domains
View OnlyView the list of guest domains
NoneNot allowed to access guest domains
Remote AssistanceFull
  • Enable remote access
  • Disable remote access
View OnlyView the Remote Assistance page
NoneNot allowed to access remote assistance
BrandingFull
  • Add logo or email
  • Edit logo or email
View OnlyView the Branding page
NoneNot allowed to access the Branding page
API Clients & ResourcesFull
  • Add API Clients
  • Edit or Delete API Clients
  • Manage Resources
  • Revoke Access Tokens
View OnlyView the API Client and Resource details
NoneNot allowed to access API Clients & Resources
CXO InsightFullAccess and view information in the Executive Insights app
NoneNot allowed to access the Executive Insights app
Related Articles
About ZIdentity Admin RolesAdding ZIdentity Admin RolesAdmin Roles and PermissionsAssigning CXO Insight User Role