Fortinet black logo

Admin Profiles

Copy Link
Copy Doc ID 7231d54a-211f-11ea-9384-00505692583a:86832
Download PDF

Admin Profiles

Use administrator profiles to control administrator access privileges to system features. When you create an administrator account, you assign a profile to the account.

You cannot modify or delete the following predefined administrator profiles:

  • Super Admin has access to all functionality.
  • Read only has read-only access.

Only the Super Admin can create, edit, and delete administrator profiles. New users can create, edit, and delete administrator profiles if they are assigned the Read Write privilege in System > Admin Profiles.

The Menu Access section has the following settings:

None

User cannot view or make changes to the system.

Read Only

User can view but not make any change to the system, except session-related user settings such as Table Customization/Dashboard/Attack Map filter.

Read Write

User can view and make changes to the system.

The CLI Commands section has the following settings:

None

User cannot execute CLI commands.

Execute

User can execute CLI commands.

To create a new Administrator Profile:
  1. Go to System > Admin Profiles.
  2. Click Create New.
  3. Specify the Profile Name.
  4. If you wish, add a Comment.
  5. Specify the privileges for Menu Access:
    • Dashboard
      • Dashboard
    • Deception
      • Customization
      • Deception OS
      • Deployment Network
      • Deployment Wizard
      • Decoy & Lure Status
      • Decoy Map
      • Whitelist
    • Incident
      • Analysis
      • Campaign
      • Attack Map
    • Fabric
      • FortiGate Integration
      • Quarantine Status
      • IOC Export
    • Network
      • Interfaces
      • System DNS
      • System Routing
    • System
      • Administrators
      • Admin Profiles
      • Certificates
      • LDAP Servers
      • RADIUS Servers
      • Mail Server
      • SNMP
      • FortiGuard
      • Settings
      • Login Disclaimer
      • System Settings
      • Table Customization
    • Log
      • All Events
      • Log Servers
  6. Specify the privileges for CLI Commands:
    • Configuration
      • Set
      • Unset
    • System
      • Reboot
      • Shutdown
      • Reset Configuration
      • Factory Reset
      • Firmware Upgrade
      • Reset Widgets
      • IP Tables
      • test-network
      • usg-license
      • Upload VM Firmware License
      • Resize VM Hard Disk
      • Set Confirm ID for Windows VM
      • List VM License
      • Show VM Status
      • VM reset
      • DC Image Status
      • Set Maintainer
      • Set Timeout for Remote Auth
      • Data Purge
      • Log Purge
      • DMZ Mode
      • fdn-pkg
    • Utilities
      • TCP Dump
      • Trace Route
  7. Click Save.

Admin Profiles

Use administrator profiles to control administrator access privileges to system features. When you create an administrator account, you assign a profile to the account.

You cannot modify or delete the following predefined administrator profiles:

  • Super Admin has access to all functionality.
  • Read only has read-only access.

Only the Super Admin can create, edit, and delete administrator profiles. New users can create, edit, and delete administrator profiles if they are assigned the Read Write privilege in System > Admin Profiles.

The Menu Access section has the following settings:

None

User cannot view or make changes to the system.

Read Only

User can view but not make any change to the system, except session-related user settings such as Table Customization/Dashboard/Attack Map filter.

Read Write

User can view and make changes to the system.

The CLI Commands section has the following settings:

None

User cannot execute CLI commands.

Execute

User can execute CLI commands.

To create a new Administrator Profile:
  1. Go to System > Admin Profiles.
  2. Click Create New.
  3. Specify the Profile Name.
  4. If you wish, add a Comment.
  5. Specify the privileges for Menu Access:
    • Dashboard
      • Dashboard
    • Deception
      • Customization
      • Deception OS
      • Deployment Network
      • Deployment Wizard
      • Decoy & Lure Status
      • Decoy Map
      • Whitelist
    • Incident
      • Analysis
      • Campaign
      • Attack Map
    • Fabric
      • FortiGate Integration
      • Quarantine Status
      • IOC Export
    • Network
      • Interfaces
      • System DNS
      • System Routing
    • System
      • Administrators
      • Admin Profiles
      • Certificates
      • LDAP Servers
      • RADIUS Servers
      • Mail Server
      • SNMP
      • FortiGuard
      • Settings
      • Login Disclaimer
      • System Settings
      • Table Customization
    • Log
      • All Events
      • Log Servers
  6. Specify the privileges for CLI Commands:
    • Configuration
      • Set
      • Unset
    • System
      • Reboot
      • Shutdown
      • Reset Configuration
      • Factory Reset
      • Firmware Upgrade
      • Reset Widgets
      • IP Tables
      • test-network
      • usg-license
      • Upload VM Firmware License
      • Resize VM Hard Disk
      • Set Confirm ID for Windows VM
      • List VM License
      • Show VM Status
      • VM reset
      • DC Image Status
      • Set Maintainer
      • Set Timeout for Remote Auth
      • Data Purge
      • Log Purge
      • DMZ Mode
      • fdn-pkg
    • Utilities
      • TCP Dump
      • Trace Route
  7. Click Save.