Customize Permissions for System and Network Administrators

You can fine-tune the permissions for System and Network administrators in your Airwall secure network.

System and Network administrators have a set of permissions by default in the Conductor. You can customize what these permissions are by default, and you can customize the permissions for individual system and network administrators.

Supported Roles
System Administrators with Can edit user permissions enabled.

Customize Default Role Permissions

You can set the default permissions that are given to people who are newly assigned the system and network administrator roles in the Conductor.
Note: Default user permissions apply only to people currently being added to a role (both new users and users who are changing roles). It does not change the permissions of people already assigned that role. The defaults can be modified as a user is created if the person making the change has "Can edit user permissions" permission.
  1. Go to Settings > Authentication.
  2. Under Default user permissions, select Edit Settings.
  3. Check the permissions you want new people to have by default when they are assigned these roles.


    Set default permissions on the Conductor Settings page

  4. Select Update to save.

Customize Permissions for individual System and Network Administrators

If you are a system administrator with Can edit user permissions active, you can customize the permissions for system and network administrators.
  1. Go to People, select a person to open their page, and then select Edit Settings.
  2. Under User permissions, check or clear the permissions you want this person to have.
    System Administrator customizable permissions

    Set Custom permissions for a System Administrator on their people page

    Network Administrator customizable permissions

    Set Custom permissions for a Network Administrator on their people page

    For more information about these permissions, see Customizable Permissions Descriptions.

  3. Select Update Settings.

Customizable Permissions Descriptions

These are the permissions that can be customized for people assigned the System or Network Administrator roles.

Permission Description
For System Administrators:
Can edit user permissions Can edit Conductor default permissions and permissions for individual users, including assigning user roles and customizing their permissions. Can also create new overlay networks and assign them to a network admin to manage trust.
Can edit system configuration Administrator can edit Conductor Settings, including High Availability (HA), email server, remote logging, authentication, or any other settings in Settings > General.
Can create and configure cloud features Can create and configure cloud Airwall Gateways, and create an HA-paired Conductor in the cloud.
Can update Conductor firmware This option is available if you have checked Can edit system configuration. Can update the Conductor software and Airwall Edge Service firmware from Settings > Firmware updates
For Network Administrators:
Can view full user interface When clear, the user sees a simplified, easier-to-use view in the Conductor. For a description of the simplified view, see Set a Streamlined View for a Network Administrator.
Can view and edit unassigned Airwalls Can view or edit any Airwall Edge Services that are not assigned to any overlay networks, including adding the devices in these Airwall Edge Services to any overlay networks they have permission to.
Can revoke and delete or re-activate Airwalls Requires that Can view and edit unassigned Airwall is checked. Can revoke, delete, and re-activate Airwall Edge Services in their overlay networks, and can view and reactivate any revoked Airwall Edge Services .
Can provision and manage Airwalls Requires that Can view and edit unassigned Airwall is checked. Can view and provision provisioning requests, and can manage unmanaged Airwall Edge Services.
Can view and edit bypass destinations Can view and edit any bypass destinations.
Can view and edit Airwall groups and relay rules Can view and edit Airwall groups and relay rules for Airwall Edge Services in their overlay networks.
Can send Airwall Invitations Can send Airwall Invitations to invite users to connect to the Airwall secure network and gain access to the devices in their overlay networks.