Fortinet black logo

Administration Guide

Permissions

Permissions

The below table lists the default permissions for the predefined administrator profiles.

When Read-Write is selected, the user can view and make changes to the FortiAnalyzer system. When Read-Only is selected, the user can only view information. When None is selected, the user can neither view or make changes to the FortiAnalyzer system.

Setting

Predefined Administrator Profile

Super User

Standard User

Restricted User

System Settings

system-setting

Read-Write

None

None

Administrative Domain

adom-switch

Read-Write

Read-Write

None

Device Manager

device-manager

Read-Write

Read-Write

Read-Only

Add/Delete/Edit Devices/Groups

device-op

Read-Write

Read-Write

None

Log View/FortiView

log-viewer

Read-Write

Read-Write

Read-Only

FortiSOC

event-management

Read-Write

Read-Write

Read-Only

Create & Update Incidents

update-incidents

Read-Write

Read-Write

None

Triage Event

triage-events

Read-Write

Read-Write

None

Reports

report-viewer

Read-Write

Read-Write

Read-Only

Run Report

run-report

Read-Write

Read-Write

None

Fabric View

fabric-viewer

Read-Write

Read-Write

Read-Only

CLI only settings

device-wan-link-load-balance

Read-Write

Read-Write

Read-Only

device-ap

Read-Write

Read-Write

Read-Only

device-forticlient

Read-Write

Read-Write

Read-Only

device-fortiswitch

Read-Write

Read-Write

Read-Only

realtime-monitor

Read-Write

Read-Write

Read-Only

adom-lock

Read-Write

Read-Write

Read-Only

device-policy-package-lock

Read-Write

Read-Write

Read-Only

extension-access

Read-Write

Read-Write

None

fortirecorder-setting

Read-Write

Read-Write

None

execute-playbook

Read-Write

Read-Write

None

script-access

Read-Write

Read-Write

None

Permissions

The below table lists the default permissions for the predefined administrator profiles.

When Read-Write is selected, the user can view and make changes to the FortiAnalyzer system. When Read-Only is selected, the user can only view information. When None is selected, the user can neither view or make changes to the FortiAnalyzer system.

Setting

Predefined Administrator Profile

Super User

Standard User

Restricted User

System Settings

system-setting

Read-Write

None

None

Administrative Domain

adom-switch

Read-Write

Read-Write

None

Device Manager

device-manager

Read-Write

Read-Write

Read-Only

Add/Delete/Edit Devices/Groups

device-op

Read-Write

Read-Write

None

Log View/FortiView

log-viewer

Read-Write

Read-Write

Read-Only

FortiSOC

event-management

Read-Write

Read-Write

Read-Only

Create & Update Incidents

update-incidents

Read-Write

Read-Write

None

Triage Event

triage-events

Read-Write

Read-Write

None

Reports

report-viewer

Read-Write

Read-Write

Read-Only

Run Report

run-report

Read-Write

Read-Write

None

Fabric View

fabric-viewer

Read-Write

Read-Write

Read-Only

CLI only settings

device-wan-link-load-balance

Read-Write

Read-Write

Read-Only

device-ap

Read-Write

Read-Write

Read-Only

device-forticlient

Read-Write

Read-Write

Read-Only

device-fortiswitch

Read-Write

Read-Write

Read-Only

realtime-monitor

Read-Write

Read-Write

Read-Only

adom-lock

Read-Write

Read-Write

Read-Only

device-policy-package-lock

Read-Write

Read-Write

Read-Only

extension-access

Read-Write

Read-Write

None

fortirecorder-setting

Read-Write

Read-Write

None

execute-playbook

Read-Write

Read-Write

None

script-access

Read-Write

Read-Write

None