Scoped Admin Roles

Modified on Tue, 6 Oct at 3:52 PM

A Scoped Admin Role delegates Admin access to one Active Directory Group — but only for the Service Groups and Automation Resources you explicitly link to it, not the whole Portal.


TABLE OF CONTENTS



Introduction

Members of the linked AD Group can administer exactly the Service Groups and Automation Resources you choose — everything else in the Portal stays hidden from them, including other Service Groups.




Fields

  • Name
    • The Name of this Scoped Admin Role.


  • AD Group Name
    • The Active Directory or Entra ID Group whose Members receive this scoped Access.


  • Service Groups
    • Which Service Groups this Role can administer.


  • Azure Credentials
    • Which Azure Automation Credentials this Role can manage.


  • SCO Instances
    • Which SCO Server Instances this Role can manage.


  • PowerShell Instances
    • Which PowerShell Instances this Role can manage.




Validation Rules

Name and AD Group Name are required. At least one Service Group is required. On top of that, at least one Azure Credential, SCO Instance or PowerShell Instance is required — a Scoped Admin Role always needs something to actually administer.


See our Authorization (Settings) Article for the global Admin Group


Was this article helpful?

That’s Great!

Thank you for your feedback

Sorry! We couldn't be helpful

Thank you for your feedback

Let us know how can we improve this article!

Select at least one of the reasons
CAPTCHA verification is required.

Feedback sent

We appreciate your effort and will try to fix the article