The Device Rights dialog box lets you control the operations that the selected administrator can perform on devices. For more information on quick task rights, see Quick Task Rights.
Specify the Device folders (contexts) that you want the administrator’s Device rights to apply to. To select a folder, click Add to display the Contexts dialog box, browse for and select the folder (or multiple folders), then click OK. The rights also apply to the folder’s subfolders.
The Privileges section lets you grant the selected administrator rights to work with devices, including device groups and folders listed in the Contexts section.
The following rights are available:
RIGHT |
OPERATIONS CONTROLLED BY THE RIGHT |
NOTES |
---|---|---|
View Leaf |
|
Setting the View Leaf right to Deny forces all other Device rights to Deny. The View Leaf right must be set to Allow to perform any other device operations. |
Modify |
|
To copy device settings, the administrator also needs the Modify Settings right. |
Create/Delete |
|
|
Modify Folders |
|
|
Create/Delete Folders |
|
Setting the Create/Delete Folders right to Allow forces the Modify Folders right to Allow. This means that an administrator who creates a folder also receives rights to modify it. |
Modify Groups |
|
To change a device group’s description, an administrator needs this right and the Modify right. |
Create/Delete Groups |
|
Setting the Create/Delete Groups right to Allow forces the Modify Groups right to Allow. This means that an administrator who creates a group also receives rights to modify it. |
Modify Group Membership |
|
|
Modify Dynamic Group |
|
|
Modify Settings |
|
This right applies to devices and device folders. It does not apply to device groups because device groups do not have a Settings tab. |
View Audit Log |
|
This right does not allow the administrator to view event details. To view event details, the administrator must have the View Audit Event right. |
View Audit Events |
|
Setting the View Audit Events right to Allow forces the View Audit Log right to Allow. |
Configure Audit Settings |
|
|
Assign Bundles |
|
To assign bundles to devices, groups, and folders, an administrator needs this right and the Bundle Rights – Assign Bundles right. In other words, the administrator needs Assign Bundle rights for the bundle and the device to which the bundle is being assigned. |
View Detailed Inventory |
|
This right controls view-only access. If you want an administrator to be able to edit the detailed inventory, the administrator needs the Modify right. |
Assign Policies |
|
To assign policies to devices, groups, and folders, an administrator needs the following rights:
In other words, an administrator needs Assign Policy rights for the policy and the device to which the policy is being assigned, and he needs the Manage Configuration Policies or Manage Security Policies right depending on whether the policy is a Configuration or Security policy. |
Geolocation |
|
|
View Activation Lock Bypass Code |
|
|
Assign Locations |
|
This right does not apply to device groups because device groups do not have a Locations tab. |
Manage ERI |
|
|