Protected object permissions
You can enable protected object permissions to allow administrators with the permission enabled to mark specific policies and objects as protected, preventing other administrators without protected object permissions from being able to edit those policies/objects.
Administrators without protected objects permissions are still able to select protected objects within a policy.
This topic includes the following:
Enabling protected object permissions
To enable protected objects permissions:
-
In the FortiManager CLI, enable protected object permission visibility:
config system global set gui-object-protect enable end
-
Go to Systems settings > Admin Profile and create or edit an admin profile.
-
Enable the Protected Objects option.
-
Assign the admin profile to an administrator
To configure an administrator profile with protected object permissions in the CLI:
config system admin profile edit <profile name> .... set protected-objects <enable/disable> end
Marking policies and objects as protected
To mark policies and objects as protected:
-
Log in as the administrator and go to Policy & Objects > Policy Package.
-
Edit an existing policy, and enable the Protected option, then save the policy.
You can see that the object has the Enabled status in the Protected column in the policy table.
-
Go to Policy & Objects, and add the protected object for the policy objects.
Users without protected object permissions
-
When object protection mode is enabled, users without the Protected Objects permission will have read-only access to the protected objects.
-
When viewing a protected object, the Protected Objects toggle is not available and you cannot edit or save the object.
-
In policy packages, you can use protected objects inside the policy even without the Protected Objects permission.