Adding an IAM user group
Create a group of asset and portal permissions, and then assign users to the group.
To create an user group:
- Go to IAM User Groups.
The IAM User Groups pane is displayed.
- Click ADD IAM USER GROUP. The Add IAM User Group pane is displayed.
- In the Group Name field, enter a name for the group.
- (Optional) In the Description field, describe the group.
- (Optional) Set the Status to Disabled. The status is Active by default.
- Click Next.
- From the Asset Permissions dropdown, select an asset group. See Asset and portal permissions.
- Configure the portal permissions.
- In the portal permissions table, click the Edit button in the portal row.
Permission Description Allow Portal Access Toggle Yes to allow access to a portal.
Access Type The Access Type is defined by the portal. For example, the access types for Asset Management are:
Admin
Read/Only
Read/Write
Whereas the access types for FortiOS SSO are:
SuperAdmin
Read Only
Additional Permission Additional permissions vary depending on the portal.
Asset Management:
Recieve Renewal Notification
FortiCare (Read Only or Read/Write)
Customer Serivce
Technical Assistance
RMA/DOA
Some portals have user roles that are specific to that portal. When a portal has a unique user role, the Custom option is displayed. For information about the role, see the product's documentation.
- Click Confirm.
- In the portal permissions table, click the Edit button in the portal row.
- Configure the Cloud Management & Services permissions.
- Click the plus sign (+).
- Select a service from the list, and click ADD.
- Click the Edit button, and configure the portal permissions.
Permission Description Allow Portal Access Toggle Yes to grant access to the service. AccessType The Access Type is defined by the portal. For example, the access types for Asset Management are:
Admin
Read/Only
Read/Write
Whereas the access types for FortiOS SSO are:
SuperAdmin
Read Only
- Click Confirm.
- Click Next. The Add IAM user(s) page is displayed.
- Assign users to the group.
- Click Add User.
- (Optional) Click Filter users by Group, to view users in a group. Selecting a user in a group will remove the user from that group.
- (Optional) Enter a username in the search bar, and enter the user name. As you type, partial results are returned.
- Select the users and click Add.
- Click Next.The Confirmation page is displayed.
- Review the group permissions, and click Confirm.
- (Optional) Click Add Another Group.