---
title: "Managing Role-Based Access Control"
canonical: "https://docs.infoblox.com/space/BloxOneCloud/35463223/Managing%20Role-Based%20Access%20Control"
format: markdown
---
Infoblox Portal offers role-based access control, allowing you to manage user access according to roles and permissions. By defining access policies, you can limit service and resource related responsibilities to specific user roles and groups. For example, Infoblox Threat Defense administrator permissions (as defined in the **TD Administrator Role**) can be restricted to the Infoblox Threat Defense admin user group (**ib-td-admin**), while read-only access for viewing configurations and reports is permitted for the Infoblox Threat Defense user group (**ib-td-user**). Similarly, Universal DDI administrator permissions (as defined in the **DDI Administrator Role**) are limited to the Universal DDI admin user group (**ib-ddi-admin**), with read-only access granted to the Universal DDI user group (**ib-ddi-user**) solely for viewing configurations and reports. 

To empower administrators to oversee and control a specific part of the overall environment within the organization, you can configure granular permissions by utilizing compartments within your Infoblox Platform account. If your organization’s infrastructure requires divisional teams to manage their own sets of users and resources, you can create access views and assign access policies to specific user groups. This enables users to access and manage their respective resources within these access viewss. By utilizing access viewss, your corporate admins retain control over the entire corporate infrastructure, while divisional admins and users can independently manage their designated resources without gaining excessive access to other areas. The access view feature can therefore effectively limit visibility and control while granting autonomy to relevant users. For information, see *[Configuring Access Views](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneCloud/pages/680362523)*[.](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneCloud/pages/680362523) 

This system of role-based access control is primarily focused on service and resource accessibility, granting explicit permissions for users or groups based on their responsibilities within your organization related to viewing, starting and stopping services, or configuring tasks and features.

Infoblox<span style="color: #000000"> Portal provides several default user roles, user groups, and access policies as a quick-start configuration, so you can quickly assign new users to user group(s) for them to gain access to relevant services and tasks. All default user groups are predefined in quick-start access policies that grant access to specific services and authorize specific users to a set of permissions, so they can perform specific responsibilities based on their roles. For example, the predefined </span><span style="color: #000000">**Access Control Administrators Policy**</span><span style="color: #000000"> applies the </span><span style="color: #000000">**Access Control Administrators Role**</span><span style="color: #000000"> to the access control admin user group (</span><span style="color: #000000">**ib-access-control-admin**</span><span style="color: #000000">), which grants access to all users in the</span><span style="color: #000000">** ib-access-control-admin**</span><span style="color: #000000"> group permissions to view and configure licenses, users, user groups, and access policies. The </span>Infoblox<span style="color: #000000"> Portal offers a few other access policies based on your license entitlements. You can use these quick-start configurations to quickly onboard your new users by placing them in their respective user groups, so they can gain access to the services to perform corresponding tasks. For more information, see </span><u><span style="color: #000000">*[Configuring Access Policies](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneCloud/pages/35367585)*</span></u><span style="color: #000000">.</span>

<span style="color: #000000">To set up role-based access control, use the following workflow to complete the tasks:</span>

1. <span style="color: #000000">Create new users and assign them to their respective user group(s) based on their respective roles and responsibilities within your organization. All users must belong to at least one user group. For more information, see </span><span style="color: #000000">*[Configuring Users](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneCloud/pages/35431374)*</span><span style="color: #000000">.</span>
2. <span style="color: #000000">Review the default user groups and create additional groups (if needed) based on your business requirements and user responsibilities. For more information, see </span><u><span style="color: #000000">*[Configuring User Groups](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneCloud/pages/35464039)*</span></u><span style="color: #000000">.</span>
3. Optionally, create access views in your Infoblox Platform account to address granular access control for divisional teams. For information, see *[Configuring Access Views](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneCloud/pages/680362523)*.
4. <span style="color: #000000">Review the default access policies and create additional access policies (if needed) by applying user roles to respective user groups. Note that an access policy grants all users in a user group a set of permissions defined in the user role, so the users can access the services and perform the tasks associated with the selected user role. For more information, see </span><u><span style="color: #000000">*[Configuring Access Policies](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneCloud/pages/35367585)*</span></u><span style="color: #000000">. </span>
5. <span style="color: #000000">Create new user roles if the predefined one do not fit your organization needs. For more information, see </span><span style="color: #000000">*[Creating Roles](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneCloud/pages/35366719)*</span><span style="color: #000000">.</span>

<span style="color: #000000">Using role-based user access control, you can also define service account users and assign service API keys to them to facilitate API authentication. Service users are account users you use to communicate with the </span>Infoblox <span style="color: #000000">API when performing specific tasks. For example, you can use a service API key to authenticate an API call to automate a process that generates reports on the </span>Infoblox<span style="color: #000000"> Portal and sends the report to yourself via email. The service API key is the authentication token key that you use in your API request for authentication purposes. You can also create service users and service API keys for user management purposes. For example, you can create a service user called "delete user" and associate this user with a service API key to delete invalid users in a systematic manner and automate the cleanup process of invalid users. Invalid users can be those who have left your company or those who are not allowed to log in to your system for specific reasons. For information about service API keys, see</span><span style="color: #ff0000"> </span><span style="color: #ff0000">*[Configuring Service API Keys](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneCloud/pages/35397908)*</span><span style="color: #ff0000">.</span>

<span style="color: #000000">To set up service users and service API keys, complete the following:</span>

1. <span style="color: #000000">Create a service account user. For more information, see</span><span style="color: #ff0000"> </span><span style="color: #000000">*[Configuring Users](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneCloud/pages/35431374)*</span><span style="color: #000000">.</span>
2. <span style="color: #000000">Create a service API key and assign it to a service user. For more information, see</span><span style="color: #ff0000"> </span><span style="color: #ff0000">*[Configuring Service API Keys](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneCloud/pages/35397908)*</span><span style="color: #ff0000">.</span>