Already a NinjaOne customer? Log in to view more guides and the latest updates.

NinjaOne Accounts: User Roles

Topic

This article explains how to assign permissions to end users and technicians through roles. 

If you would like to learn more about assigning permissions individually, rather than through a role, refer to the Managing Permissions section of NinjaOne User Management: Resource Catalog 

Before you get started with this article, you should have already created a technician or end user account in NinjaOne. If you have not yet done so, refer to the Getting Started section of NinjaOne User Management: Resource Catalog.

Environment

NinjaOne Platform

Description

NinjaOne allows system administrators to create numerous permission templates, referred to as roles, that you can assign to both new and existing NinjaOne technicians or end users. You can use roles for a variety of use cases, including customer access, apprentices, audits, and third-party collaboration. These permissions determine their level of access to different features and functionality within NinjaOne.

When you assign a user to one or more roles, you cannot edit the individual permissions for each user. You must control permissions from the role configuration page, which affects all members assigned to this role. If you need to configure different permissions for a technician in a role, you must remove the technician from the role and either assign them to a new role or manage their permissions individually.
By default, system administrators will have access to additional dashboard monitoring.

Index

Select a topic to learn more:

Create a Technician or End User Role

Using a template is the easiest way to set up a new role. Templates are completely customizable, regardless of which one you select.

  • Blank Template: This template has no predefined permissions.
  • Full Permissions Template: This template includes all predefined highest-level permissions. 

To create a new role from a template, perform the following steps:

  1. To get started, navigate to Administration → Accounts and open the Technician roles or End users roles tab.
  2. Click Create Role and select either Blank Template or Full Permissions Template from the drop-down menu.
create role.png
Figure 1: Create a new role from a blank template or full permissions template (click to enlarge)

Creating a Blank Template

Select the Blank Template option from the Create role drop-down menu to customize each permission. Then, use the following instructions to configure it.

  1. The General section will be open by default. Provide a unique identifier in the Name field. Optionally, provide a summary of the role's purpose in the Description field. 
  2. If there are existing accounts in NinjaOne that you want to add to this role, open the Members section and click Add Members. In the resulting dialog, select the checkboxes next to the end users you want to add to this role, and then click Add Selected Members.

    If you add a user to multiple roles, their permissions will default to the highest level of access amongst the assigned roles. For example, if a user is a member of a role that does not have remote access permissions and is also a member of a role that does, NinjaOne will use the higher-permission role that grants access. The user will have remote access permissions.
create role_members.png
Figure 2: Add members to a role (click to enlarge)
  1. In Permissions, click through each section to enable specific permissions.
If you grant a user Create permissions for an item, they are required by default also to have View and Update permissions for that item.

Managing Roles

After you have created a role, select the checkbox next to the role name to review the following management options:

  • Edit Selected Role: Open the role configuration page to update permissions or members.
  • Copy Selected Role: Create a new role that copies the permissions from the selected role.
  • Delete Selected Roles: Remove the role from use.
edit roles.png
Figure 3: Manage your roles (click to enlarge)

Assign a Role via the Account Configuration Page

When creating or editing roles, you can add an end user or technician from the Members section. You can also add one or more roles when you are creating or editing a technician or end user account. 

Assigning a role will overwrite any previously configured permissions for that account. 

To assign a role from the account configuration page, perform the following steps:

  1. Open the account configuration page for either a technician or end user.
  2. Open the Roles section and click Add Role.
  3. In the resulting dialog, select one or more roles by selecting the checkbox next to the role name, and then click Add Selected Role. 

add role from account editor.png
Figure 4: Assign a role from the account configuration page (click to enlarge)

Remove a Member From a Role

After you add members to a role, you can remove them from either the role or the individual account configuration page. 

To remove a member from the role configuration page:

  1. Open the Members section.
  2. Select the checkbox next to the name of one or more members.
  3. Click Remove Selected Member(s).
  4. Click Confirm in the resulting dialog.
  5. Click Save Changes.

remove members from a role.png
Figure 5: Remove members from a role

To remove a role from the account configuration page:

  1. Open the Roles section.
  2. Select the checkbox next to the name of one or more roles.
  3. Click Remove Selected Role.
  4. Click Save Changes.

remove roles from account.png
Figure 6: Remove roles from an account

Example Permissions

The following examples show common ways to manage user permissions for IT departments so you can limit access to only the functionality that your various IT departments need.

Configure Separate Permissions for Different Technician Levels

Set these permissions from the role configuration page in the Devices section. If you want to control access to specific device types, you must select "No Access" for Create New Devices and Default Access, and then select the necessary access level from the device type drop-down menu. 

access permission for a single device type.png
Figure 7: Set permissions for specific device types

The following list provides an example of how you can set permissions for different technician levels:

  • Role "Level 1" has access to workstations.
  • Role "Level 2" has access to servers.
  • Role "Level 3" has access to network devices.

Configure Permissions for Users Who Need Ticketing or Reporting Information Only

Enable the Ticketing section and select the options from one or more drop-down menus. Enable the System section and select an option from the Manage Reports drop-down menu.

Business Unit Permissions: Limit Access by Department

Enable the Organizations section and select an option for Default Access to control permissions to all organizations.

If you want to permit access to only specific organizations, select No Access from the Create New Organizations and Default Access drop-down menus. Then, select the checkboxes next to the organizations and click Edit Permissions.

access permission for a single organization.png
Figure 8: Set permissions for specific organizations

Additional Resources

Refer to the following resources to learn more about user management: 

FAQ

Next Steps