EXAMPLE: Create an elevated global admin role

Even if several Global Administrators will use sapio365, consider assigning them sapio365 RBAC roles for their day-to-day work.

This approach lets you:

  • Require ticket information when a Global Administrator makes a change in sapio365.

  • Use a single dedicated registered application in Entra as the RBAC credential, rather than requiring each Global Administrator to elevate their session and create a separate registered application. This is especially useful for teams, such as managed service providers (MSPs), that manage multiple customer tenants.

Set up sapio365 Collaboration

You can define and use sapio365 RBAC roles locally. However, you must configure sapio365 Collaboration for users working remotely, such as from separate Windows sessions or computers, to use their assigned roles.

Collaboration centralizes RBAC information and enables the use of custom roles across sapio365 users. It also lets you:

Learn about sapio365 collaboration here.

Create the role

  1. In the Dashboard, open RBAC > Configuration.

  2. Click Create Role.

  3. Enter a role name and description.

  4. Select an existing credential, or create a new credential. You can configure the same role with multiple credentials. Assigned users will see each credential configuration as a separate role.

  5. Select the options to:

    • Log data-access activity. All write actions are logged automatically.

    • Enforce the role.

    • Require a ticket number when users save changes.

  6. Clear the last option to allow the role to apply to the broadest scope of actions, including all users, groups, and sites.

    • Unchecking this option eliminates the need to set scopes to the role.

  7. Click Full Privileges to grant all available permissions, then click OK.

create-admin-role.jpg

Assign users or groups

Select the Global Administrator role, then assign users directly or through group membership. For details, see Assign users or groups.