Fortinet black logo

Admin Profiles

Copy Link
Copy Doc ID a771cc57-22b9-11eb-96b9-00505692583a:86832
Download PDF

Admin Profiles

Use administrator profiles to control administrator access privileges to system features. When you create an administrator account, you assign a profile to the account.

You cannot modify or delete the following predefined administrator profiles:

  • Super Admin has access to all functionality.
  • Read only has read-only access.

Only users with the Super Admin profile can create, edit, and delete administrator profiles. Users can create, edit, and delete administrator profiles if they have Read Write privilege in their profile.

The Menu Access section has the following settings:

None

User cannot view or make changes to that page.

Read Only

User can view but not make any change to that page, except session-related user settings such as Table Customization, Dashboard, or Attack Map filter.

Read Write

User can view and make changes to that page.

The CLI Commands section has the following settings:

None

User cannot execute CLI commands.

Execute

User can execute CLI commands.

To create an Administrator Profile:
  1. Go to System > Admin Profiles.
  2. Click Create New.
  3. Specify the Profile Name.
  4. If you wish, add a Comment.
  5. Specify the privileges for Menu Access:
    • Dashboard
      • Dashboard
    • Deception
      • Customization
      • Deception OS
      • Deployment Network
      • Deployment Wizard
      • Decoy & Lure Status
      • Decoy Map
      • Whitelist
    • Incident
      • Analysis
      • Campaign
      • Attack Map
    • Fabric
      • FortiGate Integration
      • Quarantine Status
      • IOC Export
    • Network
      • Interfaces
      • System DNS
      • System Routing
    • System
      • Administrators
      • Admin Profiles
      • Certificates
      • LDAP Servers
      • RADIUS Servers
      • Mail Server
      • SNMP
      • FortiGuard
      • Settings
      • Login Disclaimer
      • System Settings
      • Table Customization
    • Log
      • All Events
      • Log Servers
  6. Specify the privileges for CLI Commands:
    • Configuration
      • Set
      • Unset
    • System
      • Reboot
      • Shutdown
      • Reset Configuration
      • Factory Reset
      • Firmware Upgrade
      • Reset Widgets
      • IP Tables
      • test-network
      • usg-license
      • Upload VM Firmware License
      • Resize VM Hard Disk
      • Set Confirm ID for Windows VM
      • List VM License
      • Show VM Status
      • VM reset
      • DC Image Status
      • Set Maintainer
      • Set Timeout for Remote Auth
      • Data Purge
      • Log Purge
      • DMZ Mode
      • fdn-pkg
    • Utilities
      • TCP Dump
      • Trace Route
  7. Click Save.

Admin Profiles

Use administrator profiles to control administrator access privileges to system features. When you create an administrator account, you assign a profile to the account.

You cannot modify or delete the following predefined administrator profiles:

  • Super Admin has access to all functionality.
  • Read only has read-only access.

Only users with the Super Admin profile can create, edit, and delete administrator profiles. Users can create, edit, and delete administrator profiles if they have Read Write privilege in their profile.

The Menu Access section has the following settings:

None

User cannot view or make changes to that page.

Read Only

User can view but not make any change to that page, except session-related user settings such as Table Customization, Dashboard, or Attack Map filter.

Read Write

User can view and make changes to that page.

The CLI Commands section has the following settings:

None

User cannot execute CLI commands.

Execute

User can execute CLI commands.

To create an Administrator Profile:
  1. Go to System > Admin Profiles.
  2. Click Create New.
  3. Specify the Profile Name.
  4. If you wish, add a Comment.
  5. Specify the privileges for Menu Access:
    • Dashboard
      • Dashboard
    • Deception
      • Customization
      • Deception OS
      • Deployment Network
      • Deployment Wizard
      • Decoy & Lure Status
      • Decoy Map
      • Whitelist
    • Incident
      • Analysis
      • Campaign
      • Attack Map
    • Fabric
      • FortiGate Integration
      • Quarantine Status
      • IOC Export
    • Network
      • Interfaces
      • System DNS
      • System Routing
    • System
      • Administrators
      • Admin Profiles
      • Certificates
      • LDAP Servers
      • RADIUS Servers
      • Mail Server
      • SNMP
      • FortiGuard
      • Settings
      • Login Disclaimer
      • System Settings
      • Table Customization
    • Log
      • All Events
      • Log Servers
  6. Specify the privileges for CLI Commands:
    • Configuration
      • Set
      • Unset
    • System
      • Reboot
      • Shutdown
      • Reset Configuration
      • Factory Reset
      • Firmware Upgrade
      • Reset Widgets
      • IP Tables
      • test-network
      • usg-license
      • Upload VM Firmware License
      • Resize VM Hard Disk
      • Set Confirm ID for Windows VM
      • List VM License
      • Show VM Status
      • VM reset
      • DC Image Status
      • Set Maintainer
      • Set Timeout for Remote Auth
      • Data Purge
      • Log Purge
      • DMZ Mode
      • fdn-pkg
    • Utilities
      • TCP Dump
      • Trace Route
  7. Click Save.