Assigning security roles and custom roles
Security roles and custom roles provide a set of tenant-level permissions to users and administrators. As a tenant administrator, you can assign roles manually from the Administration activity center or set up automatic role assignment.
Security roles control actions and access rights for users and administrators in the tenant. In addition to the tenant-level roles, there are also space roles that control user actions on content within spaces. For more information about the different types of roles, see Roles and permissions for users and administrators.
You can assign roles to individual users or groups of users from the Administration activity center.
Assigning security roles and custom roles to users
The Users section in the Administration activity center has two tabs. Tenant administrators can assign security roles from the All users tab or the Permissions tab and custom roles from the Permissions tab.
The All users tab shows a list of users who have been added or invited to the tenant. You can select one or more users to see all roles assigned to them.
Do the following:
-
In the Administration activity center, go to Users > All users.
-
Select one or more users and click Edit roles.
-
In the Edit roles dialog, select the security roles you want to assign on the User tab or Admin tab.
-
Click Save.
The users will be assigned the role at their next login.
On the Permissions tab, you see all available security roles and custom roles. You can select a role to see all users assigned to this role.
Do the following:
-
In the Administration activity center, go to Users > Permissions.
-
Click the arrow on the role you want to assign.
-
On the Users tab, click Assign.
-
Search for users by name or email and add them to the list.
-
Click Assign.
The users will be assigned the role at their next login.
Assigning security roles and custom roles to groups
Groups are defined through your identity provider and not created from the Administration activity center. Tenant administrators can assign security roles and custom roles to groups from the Permissions tab on the Users pane in the Administration activity center. When you assign a role to a group, every member of that group is granted the permissions defined by the role.
Do the following:
-
In the Administration activity center, go to Users > Permissions.
-
Click the arrow on the role you want to assign.
-
On the Groups tab, click Assign.
-
Search for groups by name and add them to the list.
-
Click Assign.
The group members will be assigned the role at their next login.
Assigning security roles and custom roles to everyone in the tenant
Tenant administrators can assign security roles and custom roles to all users in the tenant from the Auto assign column on the Permissions tab in the Administration activity center. A role assigned to a user this way is removed from the user if you set the value in the column to Off.
Do the following:
-
In the Administration activity center, go to Users > Permissions.
-
Find the role you want to assign to everyone and select Anyone at <your tenant name> in the Auto assign column.
All users will be assigned the role at their next login.
For new tenants, the following roles are automatically assigned to all users by default:
-
Automation Creator
-
Data Services Contributor
-
Steward
-
Private Analytics Content Creator
-
Shared Space Creator
-
Automl Experiment Contributor
-
Automl Deployment Contributor
Additionally, the following roles are automatically assigned through toggles in the Settings > Entitlements section of the Administration activity center:
-
Shared Space Creator
-
Private Analytics Content Creator
-
Data Services Contributor
These toggles differ from the Auto assign option in the following ways:
-
Auto assign option:
-
The role is assigned while the option is on and removed when turned off.
-
Applies to all users, which means that enabling this option will promote all Basic Users to Full Users.
-
-
Settings > Entitlements toggle:
-
The role remains assigned until manually removed, even if the toggle is turned off.
-
Applies to users with Full User entitlement only.
-