Fortinet black logo

EMS Administration Guide

Administrators reference

Administrators reference

This section contains descriptions of the fields used to configure Administrators.

Following is a description of the fields in Administration > Administrators > Add.

Option

Description

User

Select the Windows/LDAP user to configure permissions for FortiClient EMS.

Super Administrator permissions

Enable the super administrator feature to give the new Windows/LDAP user super administrator permissions.

Comment

Enter optional comments/information for the Windows/LDAP user.

Domain Access

Select or add access to a domain for the Windows/LDAP user and configure their permissions.

If you choose one or more domains in the domain access field, you must select specific permissions.

Google Domain Access

Select or add access to a domain for the Windows/LDAP user and configure their permissions.

If you choose one or more domains in the domain access field, you must select specific permissions.

General Permissions

Use the settings to configure permissions to FortiClient EMS for the selected Windows/LDAP user.

Create/Update/Delete LDAPs

Select to allow the Windows user to create, delete, and update LDAP records. Clear to disable this permission.

Create/Update/Delete custom groups

Select to allow the Windows user to create, update, and delete custom groups. Clear to disable this permission.

Create/Delete filters

Select to allow the Windows user to create and delete filters. Clear to disable this permission.

Endpoint Permissions

Use the following options to configure permissions for the selected Windows user.

Block/Unblock/Quarantine/Unquarantine/Reregister endpoints

Select to allow the Windows user to block, unblock, disconnect, quarantine, unquarantine, and reconnect endpoints. Clear to disable this permission.

Run commands on endpoints

Select to allow the Windows user to run commands on endpoints. Clear to disable this permission.

Access Software Management

Select to allow the Windows user to access the Profile Components > Manage Installers options. Clear to disable this permission.

Access CA Certificate Management

Select to allow the Windows user to access the Profile Components > Manage CA Certificates options. Clear to disable this permission.

Policy Permissions

Assign/Unassign policies

Select to allow the Windows user to assign to endpoints and unassign profiles from domains/endpoints and manage custom groups. Clear to disable this permission.

Create/Update/Delete policies

Select to allow the Windows user to create, delete, edit, and rename profiles. Clear to disable this permission.

Administrators reference

This section contains descriptions of the fields used to configure Administrators.

Following is a description of the fields in Administration > Administrators > Add.

Option

Description

User

Select the Windows/LDAP user to configure permissions for FortiClient EMS.

Super Administrator permissions

Enable the super administrator feature to give the new Windows/LDAP user super administrator permissions.

Comment

Enter optional comments/information for the Windows/LDAP user.

Domain Access

Select or add access to a domain for the Windows/LDAP user and configure their permissions.

If you choose one or more domains in the domain access field, you must select specific permissions.

Google Domain Access

Select or add access to a domain for the Windows/LDAP user and configure their permissions.

If you choose one or more domains in the domain access field, you must select specific permissions.

General Permissions

Use the settings to configure permissions to FortiClient EMS for the selected Windows/LDAP user.

Create/Update/Delete LDAPs

Select to allow the Windows user to create, delete, and update LDAP records. Clear to disable this permission.

Create/Update/Delete custom groups

Select to allow the Windows user to create, update, and delete custom groups. Clear to disable this permission.

Create/Delete filters

Select to allow the Windows user to create and delete filters. Clear to disable this permission.

Endpoint Permissions

Use the following options to configure permissions for the selected Windows user.

Block/Unblock/Quarantine/Unquarantine/Reregister endpoints

Select to allow the Windows user to block, unblock, disconnect, quarantine, unquarantine, and reconnect endpoints. Clear to disable this permission.

Run commands on endpoints

Select to allow the Windows user to run commands on endpoints. Clear to disable this permission.

Access Software Management

Select to allow the Windows user to access the Profile Components > Manage Installers options. Clear to disable this permission.

Access CA Certificate Management

Select to allow the Windows user to access the Profile Components > Manage CA Certificates options. Clear to disable this permission.

Policy Permissions

Assign/Unassign policies

Select to allow the Windows user to assign to endpoints and unassign profiles from domains/endpoints and manage custom groups. Clear to disable this permission.

Create/Update/Delete policies

Select to allow the Windows user to create, delete, edit, and rename profiles. Clear to disable this permission.