---
title: "About Admin Groups"
canonical: "https://docs.infoblox.com/space/NAG8/22250326/About%20Admin%20Groups"
format: markdown
---
All administrators must belong to an admin group. The permissions and properties that you set for a group apply to all administrators assigned to that group. You can assign a dashboard template to an admin group. A dashboard template specifies the tasks an admin group can access through the **Tasks** **Dashboard** tab when they log in to Grid Manager. For information about dashboard templates, see *<span style="color: #0000ff">[About](https://infoblox-docs.atlassian.net/wiki/spaces/NAG8/pages/22250240)</span>*[ ](https://infoblox-docs.atlassian.net/wiki/spaces/NAG8/pages/22250240)*<span style="color: #0000ff">[Dashboard](https://infoblox-docs.atlassian.net/wiki/spaces/NAG8/pages/22250240)</span>*[ ](https://infoblox-docs.atlassian.net/wiki/spaces/NAG8/pages/22250240)*<span style="color: #0000ff">[Templates](https://infoblox-docs.atlassian.net/wiki/spaces/NAG8/pages/22250240)</span>*. You can also restrict certain user groups to manage specific tasks in the **Tasks** **Dashboard** tab only. These users cannot manage other core network services through Grid Manager. For information about how to apply this restriction, see *<span style="color: #0000ff">[Creating](#)</span>* *<span style="color: #0000ff">[Limited-Access](#)</span>*[ ](#)*<span style="color: #0000ff">[Admin](#)</span>*[ ](#)*<span style="color: #0000ff">[Groups](#)</span>*.  
 To define admins who can perform specific core network service tasks, you can set up admin groups and assign them permissions for those tasks. To control when and whether certain tasks should be performed, you can add an admin group to an approval workflow and define the admins as submitters or approvers. A submitter is an admin whose tasks require approvals before execution, and an approver is an admin who can approve the submitted tasks. When you add submitter and approver groups to an approval workflow, you have control over who can perform which mission critical tasks and whether and when the tasks should be executed. For more information about how to create and configure approval workflows, see *<span style="color: #0000ff">[Configuring](https://infoblox-docs.atlassian.net/wiki/spaces/NAG8/pages/22250260)</span>*[ ](https://infoblox-docs.atlassian.net/wiki/spaces/NAG8/pages/22250260)*<span style="color: #0000ff">[Approval](https://infoblox-docs.atlassian.net/wiki/spaces/NAG8/pages/22250260)</span>*[ ](https://infoblox-docs.atlassian.net/wiki/spaces/NAG8/pages/22250260)*<span style="color: #0000ff">[Workflows](https://infoblox-docs.atlassian.net/wiki/spaces/NAG8/pages/22250260)</span>*.  
 There are three types of admin groups:

- **Superuser** – Superuser admin groups provide their members> Macro (anchor)

 with unlimited access and control of all the operations that a NIOS appliance performs. There is a default superuser admin group, called **admin-group**, with one superuser administrator, **admin**. You can add users to this default admin group and create additional admin groups with superuser privileges. Superusers can access the appliance through its console, GUI, and API. In addition, only> Macro (anchor)

 superusers can create admin groups.
- **Limited-Access** – Limited-access admin groups provide their members with read-only or read/write access to specific resources. These admin groups can access the appliance through the GUI, API, or both. They cannot access the appliance through the console.
- **Default** – When upgrading from previous NIOS releases, the appliance converts the> Macro (anchor)

 ALL USERS group to the Default Group when the ALL USERS Group contains admin accounts. The appliance does not create the Default Group if there is no permission in the ALL USERS group. The permissions associated with the ALL USERS group are moved to a newly created role called Default Role. Supported in previous NIOS releases, the ALL USERS group was a default group in which you defined global permissions for all limited-access users. This group implicitly included all limited-access users configured on the appliance.

All limited-access admin groups require either read-only or read/write permission to access certain resources, such as Grid members, and DNS and DHCP resources, to perform certain tasks. Therefore, when you create an admin group, you must specify which resources the group is authorized to access and their level of access.  
 Only superusers can create admin groups and define their administrative permissions. There are two ways to define the permissions of an admin group. You can create an admin group and assign permissions directly to the group, or you can create roles that contain permissions and assign the roles to an admin group.  
 You must create admin groups and assign them access to the cloud API and applicable permissions so they have authority over delegated objects. When you assign permissions for objects that have not been delegated, these admin groups or admin users assume applicable permissions to these un-delegated objects. For example, you can create an admin group that can access a specific set of networks while another can access another set of networks. Note that you cannot create a new admin group using the same name. For information about Cloud Network Automation, see *<span style="color: #0000ff">[Deploying](https://infoblox-docs.atlassian.net/wiki/spaces/NAG8/pages/22250574)</span>*[ ](https://infoblox-docs.atlassian.net/wiki/spaces/NAG8/pages/22250574)*<span style="color: #0000ff">[Cloud](https://infoblox-docs.atlassian.net/wiki/spaces/NAG8/pages/22250574)</span>*[ ](https://infoblox-docs.atlassian.net/wiki/spaces/NAG8/pages/22250574)*<span style="color: #0000ff">[Network](https://infoblox-docs.atlassian.net/wiki/spaces/NAG8/pages/22250574)</span>*[ ](https://infoblox-docs.atlassian.net/wiki/spaces/NAG8/pages/22250574)*<span style="color: #0000ff">[Automation](https://infoblox-docs.atlassian.net/wiki/spaces/NAG8/pages/22250574)</span>*.  
 Complete the following tasks to assign permissions directly to an admin group:

1. Create an admin group, as described in *<span style="color: #0000ff">[Creating](#)</span>*[ ](#)*<span style="color: #0000ff">[Limited-Access](#)</span>*[ ](#)*<span style="color: #0000ff">[Admin](#)</span>*[ ](#)*<span style="color: #0000ff">[Groups](#)</span>*[.](#)
2. Assign permissions to the admin group, as described in *<span style="color: #0000ff">[About](https://infoblox-docs.atlassian.net/wiki/spaces/NAG8/pages/22250317)</span>*[ ](https://infoblox-docs.atlassian.net/wiki/spaces/NAG8/pages/22250317)*<span style="color: #0000ff">[Administrative](https://infoblox-docs.atlassian.net/wiki/spaces/NAG8/pages/22250317)</span>*[ ](https://infoblox-docs.atlassian.net/wiki/spaces/NAG8/pages/22250317)*<span style="color: #0000ff">[Permissions](https://infoblox-docs.atlassian.net/wiki/spaces/NAG8/pages/22250317)</span>*[.](https://infoblox-docs.atlassian.net/wiki/spaces/NAG8/pages/22250317) Complete these tasks to assign admin roles to an admin group:
3. Create an admin role, as described in *<span style="color: #0000ff">[About](https://infoblox-docs.atlassian.net/wiki/spaces/NAG8/pages/22250330)</span>*[ ](https://infoblox-docs.atlassian.net/wiki/spaces/NAG8/pages/22250330)*<span style="color: #0000ff">[Admin](https://infoblox-docs.atlassian.net/wiki/spaces/NAG8/pages/22250330)</span>*[ ](https://infoblox-docs.atlassian.net/wiki/spaces/NAG8/pages/22250330)*<span style="color: #0000ff">[Roles](https://infoblox-docs.atlassian.net/wiki/spaces/NAG8/pages/22250330)</span>*.
4. Define permissions for the newly created admin role, as described in *<span style="color: #0000ff">[Creating](https://infoblox-docs.atlassian.net/wiki/spaces/NAG8/pages/22250330/About+Admin+Roles#AboutAdminRoles-bookmark398)</span>*[ ](https://infoblox-docs.atlassian.net/wiki/spaces/NAG8/pages/22250330/About+Admin+Roles#AboutAdminRoles-bookmark398)*<span style="color: #0000ff">[Admin](https://infoblox-docs.atlassian.net/wiki/spaces/NAG8/pages/22250330/About+Admin+Roles#AboutAdminRoles-bookmark398)</span>*[ ](https://infoblox-docs.atlassian.net/wiki/spaces/NAG8/pages/22250330/About+Admin+Roles#AboutAdminRoles-bookmark398)*<span style="color: #0000ff">[Roles](https://infoblox-docs.atlassian.net/wiki/spaces/NAG8/pages/22250330/About+Admin+Roles#AboutAdminRoles-bookmark398)</span>*[.](https://infoblox-docs.atlassian.net/wiki/spaces/NAG8/pages/22250330/About+Admin+Roles#AboutAdminRoles-bookmark398)
5. Create an admin group and assign the role to the group, as described in *<span style="color: #0000ff">[Creating](#)</span>*[ ](#)*<span style="color: #0000ff">[Limited-Access](#)</span>*[ ](#)*<span style="color: #0000ff">[Admin](#)</span>*[ ](#)*<span style="color: #0000ff">[Groups](#)</span>*

After you have created admin groups and defined their administrative permissions, you can assign administrators to the group.

- For local admins, see *<span style="color: #0000ff">[Creating](https://infoblox-docs.atlassian.net/wiki/spaces/NAG8/pages/22250304)</span>*[ ](https://infoblox-docs.atlassian.net/wiki/spaces/NAG8/pages/22250304)*<span style="color: #0000ff">[Local](https://infoblox-docs.atlassian.net/wiki/spaces/NAG8/pages/22250304)</span>*[ ](https://infoblox-docs.atlassian.net/wiki/spaces/NAG8/pages/22250304)*<span style="color: #0000ff">[Admins](https://infoblox-docs.atlassian.net/wiki/spaces/NAG8/pages/22250304)</span>*[.](https://infoblox-docs.atlassian.net/wiki/spaces/NAG8/pages/22250304)
- For remote admins, see *<span style="color: #0000ff">[About](https://infoblox-docs.atlassian.net/wiki/spaces/NAG8/pages/22250308)</span>*[ ](https://infoblox-docs.atlassian.net/wiki/spaces/NAG8/pages/22250308)*<span style="color: #0000ff">[Remote](https://infoblox-docs.atlassian.net/wiki/spaces/NAG8/pages/22250308)</span>*[ ](https://infoblox-docs.atlassian.net/wiki/spaces/NAG8/pages/22250308)*<span style="color: #0000ff">[Admins](https://infoblox-docs.atlassian.net/wiki/spaces/NAG8/pages/22250308)</span>*.

# > Macro (anchor)

> Macro (anchor)

Creating Superuser Admin Group> Macro (anchor)

s

Superusers have unlimited access to the NIOS appliance. They can perform all operations that the appliance supports. There are some operations, such as creating admin groups and roles, that only superusers can perform.  
 Note that there must always be one superuser admin account, called "admin", stored in the local database to ensure that at least one administrator can log in to the appliance in case the NIOS appliance loses connectivity to the remote admin databases such as RADIUS servers, AD domain controllers, TACACS+ servers, LDAP servers, or OCSP responders.  
 NIOS comes with a default superuser admin group (**admin-group**)**.** It also automatically creates a new admin group, **fireeye-group**, when you add the first FireEye RPZ (Response Policy Zone). Infoblox recommends that you do not add another admin group with the same name as the default or FireEye admin group. Note that the FireEye admin group is read-only and you cannot assign permissions to it. For more information about FireEye RPZs, see *<span style="color: #0000ff">[About](https://infoblox-docs.atlassian.net/wiki/spaces/NAG8/pages/22253122)</span>*[ ](https://infoblox-docs.atlassian.net/wiki/spaces/NAG8/pages/22253122)*<span style="color: #0000ff">[FireEye](https://infoblox-docs.atlassian.net/wiki/spaces/NAG8/pages/22253122)</span>* *<span style="color: #0000ff">[Integrated](https://infoblox-docs.atlassian.net/wiki/spaces/NAG8/pages/22253122)</span>*[ ](https://infoblox-docs.atlassian.net/wiki/spaces/NAG8/pages/22253122)*<span style="color: #0000ff">[RPZs](https://infoblox-docs.atlassian.net/wiki/spaces/NAG8/pages/22253122)</span>*.  
 When you install valid licenses and configure your Grid for Cloud Network Automation, NIOS enables the  
 **cloud-api-only** admin group. You can assign admin users to this group so they are authorized to send cloud API requests to the Cloud Platform Appliances. Note that you cannot delete this admin group or create a new admin group using the same name. For information about Cloud Network Automation, see *<span style="color: #0000ff">[Deploying](https://infoblox-docs.atlassian.net/wiki/spaces/NAG8/pages/22250574)</span>*[ ](https://infoblox-docs.atlassian.net/wiki/spaces/NAG8/pages/22250574)*<span style="color: #0000ff">[Cloud](https://infoblox-docs.atlassian.net/wiki/spaces/NAG8/pages/22250574)</span>*[ ](https://infoblox-docs.atlassian.net/wiki/spaces/NAG8/pages/22250574)*<span style="color: #0000ff">[Network](https://infoblox-docs.atlassian.net/wiki/spaces/NAG8/pages/22250574)</span>*[ ](https://infoblox-docs.atlassian.net/wiki/spaces/NAG8/pages/22250574)*<span style="color: #0000ff">[Automation](https://infoblox-docs.atlassian.net/wiki/spaces/NAG8/pages/22250574)</span>*.  
 You can create additional superuser admin groups, as follows:

1. From the **Administration** tab, select the **Administrators** tab -> **Groups** tab, and then click the Add icon.
2. In the *Add* *Admin* *Group* wizard, complete the following:
  - **Name:** Enter a name for the admin group.
  - **Comment:** Enter useful information about the group, such as location or department. For **fireeye-group,** NIOS displays **Group** **used** **to** **receive** **FireEye** **alerts** in this field**.**
  - **Disable:** Select this to retain an inactivated profile for this admin group in the configuration. For example, you may want to define a profile for recently hired administrators who have not yet started work. Then when they do start, you simply need to clear this check box to activate the profile.
3. Click **Next** and complete the following:
  - **Superusers:** Select this to grant the admin accounts that you assign to this group full authority to view and configure all types of data and perform all tasks.
  - **Allowed** **Interfaces**: Superusers admin groups are automatically granted access to the Infoblox GUI (Grid Manager) and API. You can specify which API the superusers group can access. Note that you must have the Cloud Network Automation or Cloud Platform license installed to configure access to the cloud API.  
**GUI:** This is selected by default. The superusers admin group automatically has full access to Grid Manager.  
**API:** This is selected by default. Note that the following options are displayed only if a cloud license is installed in the Grid.

- **API ****(WAPI/PAPI**** only)**: The superusers admin group has full access to the RESTful API and the Infoblox API by default.
- **Cloud**** API:** Select this to allow the superusers admin group to use the cloud API. This option is available only if a cloud license is installed in the Grid. Select one of the following:
  - **Cloud**** API ****only**** (no ****PAPI)**: Select this to allow the admin group to use WAPI (RESTful API) to send cloud API requests. Note that the Cloud API uses WAPI exclusively. The group has no access to the Infoblox API.
  - **Cloud**** API**** and ****PAPI**** (No ****WAPI)**: Select this to allow the admin group to send API requests and have access to the Infoblox API. However, the group cannot use WAPI to send cloud API calls.

---

**Note:** When you assign cloud API access to an admin group, the group assumes full authority over all delegated objects. You must however specifically assign object permissions to the admin group for the group to gain authority over non-delegated objects. For information about how to assign object permissions, see *<span style="color: #0000ff">[Defining](https://infoblox-docs.atlassian.net/wiki/spaces/NAG8/pages/22250317/About+Administrative+Permissions#AboutAdministrativePermissions-bookmark415)</span>*[ ](https://infoblox-docs.atlassian.net/wiki/spaces/NAG8/pages/22250317/About+Administrative+Permissions#AboutAdministrativePermissions-bookmark415)*<span style="color: #0000ff">[Object](https://infoblox-docs.atlassian.net/wiki/spaces/NAG8/pages/22250317/About+Administrative+Permissions#AboutAdministrativePermissions-bookmark415)</span>*[ ](https://infoblox-docs.atlassian.net/wiki/spaces/NAG8/pages/22250317/About+Administrative+Permissions#AboutAdministrativePermissions-bookmark415)*<span style="color: #0000ff">[Permissions](https://infoblox-docs.atlassian.net/wiki/spaces/NAG8/pages/22250317/About+Administrative+Permissions#AboutAdministrativePermissions-bookmark415)</span>*.

---

   4. Click **Next** and complete the following to define the dashboard template:

- **Dashboard ****Template**: From the drop-down list, select the dashboard template you want to assign to this superuser group. When you apply a dashboard template to an admin group, the template applies to all users in the group. The default is **None**, which means that users in this group can access all licensed tasks in the **Tasks ****Dashboard** tab if they have the correct permissions to the task-related objects. Note that if you want to delete a template, you must first unassign the template from an admin group, or select **None**, before you can delete it. For more information about dashboard templates, see *<span style="color: #0000ff">[About](https://infoblox-docs.atlassian.net/wiki/spaces/NAG8/pages/22280615/Chapter+2+Dashboards#Chapter2Dashboards-bookmark215)</span>*[ ](https://infoblox-docs.atlassian.net/wiki/spaces/NAG8/pages/22280615/Chapter+2+Dashboards#Chapter2Dashboards-bookmark215)*<span style="color: #0000ff">[Dashboards](https://infoblox-docs.atlassian.net/wiki/spaces/NAG8/pages/22280615/Chapter+2+Dashboards#Chapter2Dashboards-bookmark215)</span>*.

   5. Click **Next** to add admin email addresses if you want the appliance to send approval workflow notifications to a list of email addresses for the admin group. Complete the following in the Email Address table:  
Click the Add icon and Grid Manager adds a row to the table. Enter the email address of the admin who should receive workflow notifications. You can click the Add icon again to add more email addresses. You can also select an email address and click the Delete icon to delete it. To modify an email address, click the **Email** **Address** column and modify the existing address.

---

**Note:** When you configure an approval workflow and select **Group ****Email**** Address(es)** as the approver notification addresses, the appliance sends workflow notifications to all email addresses you have added to this table. For information, see *<span style="color: #0000ff">[Configuring](https://infoblox-docs.atlassian.net/wiki/spaces/NAG8/pages/22250260)</span>*[ ](https://infoblox-docs.atlassian.net/wiki/spaces/NAG8/pages/22250260)*<span style="color: #0000ff">[Approval](https://infoblox-docs.atlassian.net/wiki/spaces/NAG8/pages/22250260)</span>*[ ](https://infoblox-docs.atlassian.net/wiki/spaces/NAG8/pages/22250260)*<span style="color: #0000ff">[Workflows](https://infoblox-docs.atlassian.net/wiki/spaces/NAG8/pages/22250260)</span>*[ .](https://infoblox-docs.atlassian.net/wiki/spaces/NAG8/pages/22250260)

---

   6. Optionally, click **Next** to add extensible attributes to the admin group. For information, see *<span style="color: #0000ff">[About](https://infoblox-docs.atlassian.net/wiki/spaces/NAG8/pages/22250486)</span>*[ ](https://infoblox-docs.atlassian.net/wiki/spaces/NAG8/pages/22250486)*<span style="color: #0000ff">[Extensible](https://infoblox-docs.atlassian.net/wiki/spaces/NAG8/pages/22250486)</span>* *<span style="color: #0000ff">[Attributes.](https://infoblox-docs.atlassian.net/wiki/spaces/NAG8/pages/22250486)</span>*

   7. Save the configuration and click **Restart** if it appears at the top of the screen. You can do one of the following after you create a superuser admin group:

- Add local admins to the superuser group. For information, see *<span style="color: #0000ff">[Creating](https://infoblox-docs.atlassian.net/wiki/spaces/NAG8/pages/22250304)</span>*[ ](https://infoblox-docs.atlassian.net/wiki/spaces/NAG8/pages/22250304)*<span style="color: #0000ff">[Local](https://infoblox-docs.atlassian.net/wiki/spaces/NAG8/pages/22250304)</span>*[ ](https://infoblox-docs.atlassian.net/wiki/spaces/NAG8/pages/22250304)*<span style="color: #0000ff">[Admins](https://infoblox-docs.atlassian.net/wiki/spaces/NAG8/pages/22250304)</span>*.
- Assign the superuser group to remote admins. For information, see *<span style="color: #0000ff">[About](https://infoblox-docs.atlassian.net/wiki/spaces/NAG8/pages/22250308)</span>*[ ](https://infoblox-docs.atlassian.net/wiki/spaces/NAG8/pages/22250308)*<span style="color: #0000ff">[Remote](https://infoblox-docs.atlassian.net/wiki/spaces/NAG8/pages/22250308)</span>*[ ](https://infoblox-docs.atlassian.net/wiki/spaces/NAG8/pages/22250308)*<span style="color: #0000ff">[Admins](https://infoblox-docs.atlassian.net/wiki/spaces/NAG8/pages/22250308)</span>*.

# > Macro (anchor)

> Macro (anchor)

> Macro (anchor)

Creating Limited-Access Admin Groups

When you create a limited-access admin group, you can assign roles to it. The group then inherits the permissions of its assigned roles. In addition, you can assign permissions directly to the group. Only superusers can create admin groups.  
 To create a limited-access admin group:

1. From the **Administration** tab, select the **Administrators** tab -> **Groups** tab, and then click the Add icon.
2. In the *Add* *Admin* *Group* wizard, complete the following:
  - **Name:** Enter a name for the admin group.
  - **Comment:** Enter useful information about the group, such as location or department.
  - **Disable:** Select this to retain an inactivated profile for this admin group in the configuration. For example, you may want to define a profile for recently hired administrators who have not yet started work. Then when they do start, you simply need to clear this check box to activate the profile.
3. Click **Next** and complete the following:
  - **Superusers:** Clear this check box to create a limited-access admin group.
  - **Roles**: Optionally, click the Add icon to add an admin role to the admin group. In the *Role* *Selector* dialog box, select the roles you want to assign to the admin group, and then click the Select icon. Use Shift+click and Ctrl+click to select multiple admin roles. You can assign up to 21 roles to an admin group. The appliance displays the selected roles in the list box. When an admin group is assigned multiple roles, the appliance applies the permissions to the group in the order the roles are listed. Therefore if there are overlapped permissions among the roles, the appliance uses the permission from the role that is listed first and ignores the others. You can reorder the list by selecting a role and clicking the arrow keys to move the role up and down the list. To delete a role, select it and click the Delete icon.
  - **Allowed** **Interfaces**: Specify whether the admin group can use the Infoblox GUI (Grid Manager) and the API (application programming interface) to configure the appliance. Note that you must have the Cloud Network Automation or Cloud Platform license installed to configure access to the cloud API.  
**GUI:** Select this to allow the admin group to use the Infoblox GUI, Grid Manager.  
**API:** Select this to allow the admin group access to the Infoblox API. The following options are available only if a Cloud Network Automation or Cloud Platform license is active in the Grid. You must first select this option to enable the following options.
    - **API** **(WAPI/PAPI** **only)**: Select this to allow the admin group to use only the RESTful API and Infoblox API.
    - **Cloud ****API:** Select this to allow the admin group to use the cloud API. This option is available only if a Cloud Network Automation or Cloud Platform license is installed in the Grid. Select one of the following:
      - **Cloud** **API** **only** **(No** **PAPI)**: Select this to allow the admin group to use WAPI (RESTful API) to send cloud API requests. Note that the Cloud API uses WAPI exclusively. The group has no access to the Infoblox API.
      - **Cloud** **API** **and** **PAPI** **(No** **WAPI)**: Select this to allow the admin group to send API requests and have access to the Infoblox API. However, the group cannot use RESTful API to send cloud API calls.

---

**Note:** When you assign cloud API access to an admin group, the group assumes full authority over all delegated objects. You must however specifically assign object permissions to the admin group for the group to gain authority over non-delegated objects. For information about how to assign object permissions, see *<span style="color: #0000ff">[Defining](https://infoblox-docs.atlassian.net/wiki/spaces/NAG8/pages/22250317/About+Administrative+Permissions#AboutAdministrativePermissions-bookmark415)</span>*[ ](https://infoblox-docs.atlassian.net/wiki/spaces/NAG8/pages/22250317/About+Administrative+Permissions#AboutAdministrativePermissions-bookmark415)*<span style="color: #0000ff">[Object](https://infoblox-docs.atlassian.net/wiki/spaces/NAG8/pages/22250317/About+Administrative+Permissions#AboutAdministrativePermissions-bookmark415)</span>*[ ](https://infoblox-docs.atlassian.net/wiki/spaces/NAG8/pages/22250317/About+Administrative+Permissions#AboutAdministrativePermissions-bookmark415)*<span style="color: #0000ff">[Permissions](https://infoblox-docs.atlassian.net/wiki/spaces/NAG8/pages/22250317/About+Administrative+Permissions#AboutAdministrativePermissions-bookmark415)</span>*.

---

   4. Click **Next** and complete the following to define the dashboard template:

- **Dashboard****Template**: From the drop-down list, select the dashboard template you want to assign to this superuser group. When you assign a dashboard template to an admin group, the template applies to all users in the group. The default is **None**, which means that users in this group can perform all licensed tasks in the **Tasks****Dashboard** tab if they have the correct permissions to the task-related objects. Note that if you want to delete a template, you must first unassign the template from an admin group, or select **None**, before you can delete it. For more information about dashboard templates, see *<span style="color: #0000ff">[About](https://infoblox-docs.atlassian.net/wiki/spaces/NAG8/pages/22280615/Chapter+2+Dashboards#Chapter2Dashboards-bookmark215)</span>*[ ](https://infoblox-docs.atlassian.net/wiki/spaces/NAG8/pages/22280615/Chapter+2+Dashboards#Chapter2Dashboards-bookmark215)*<span style="color: #0000ff">[Dashboards](https://infoblox-docs.atlassian.net/wiki/spaces/NAG8/pages/22280615/Chapter+2+Dashboards#Chapter2Dashboards-bookmark215)</span>*.
- **Display**** Task flow ****Dashboards ****Only**: Select this check box if you want to restrict this admin group to access only the Tasks Dashboard in Grid Manager. Note that when you select this check box, users in this admin group have access to the tasks you specified in the selected dashboard template, if applicable. They cannot perform any other tasks or manage any core network services in Grid Manager the next time they log in to the system.

   5. Click **Next** to add admin email addresses if you want the appliance to send approval workflow notifications to a list of email addresses for the admin group. Complete the following in the Email Address table:

Click the Add icon and Grid Manager adds a row to the table. Enter the email address of the admin who should receive workflow notifications. You can click the Add icon again to add more email addresses. You can also select an email address and click the Delete icon to delete it. To modify an email address, click the **Email** **Address** column and modify the existing address.

---

**Note:** When you configure an approval workflow and select **Group** **Email** **Address(es)** as the approver notification addresses, the appliance sends workflow notifications to all email addresses you have added to this table. For information, see *<span style="color: #0000ff">[Creating](https://infoblox-docs.atlassian.net/wiki/spaces/NAG8/pages/22250260/Configuring+Approval+Workflows#ConfiguringApprovalWorkflows-bookmark163)</span>*[ ](https://infoblox-docs.atlassian.net/wiki/spaces/NAG8/pages/22250260/Configuring+Approval+Workflows#ConfiguringApprovalWorkflows-bookmark163)*<span style="color: #0000ff">[Approval](https://infoblox-docs.atlassian.net/wiki/spaces/NAG8/pages/22250260/Configuring+Approval+Workflows#ConfiguringApprovalWorkflows-bookmark163)</span>*[ ](https://infoblox-docs.atlassian.net/wiki/spaces/NAG8/pages/22250260/Configuring+Approval+Workflows#ConfiguringApprovalWorkflows-bookmark163)*<span style="color: #0000ff">[Workflows](https://infoblox-docs.atlassian.net/wiki/spaces/NAG8/pages/22250260/Configuring+Approval+Workflows#ConfiguringApprovalWorkflows-bookmark163)</span>*.

---

   6. Optionally, click **Next** to add or delete extensible attributes for this admin group. For information, see *<span style="color: #0000ff">[About](https://infoblox-docs.atlassian.net/wiki/spaces/NAG8/pages/22250486)</span>* *<span style="color: #0000ff">[Extensible](https://infoblox-docs.atlassian.net/wiki/spaces/NAG8/pages/22250486)</span>*[ ](https://infoblox-docs.atlassian.net/wiki/spaces/NAG8/pages/22250486)*<span style="color: #0000ff">[Attributes](https://infoblox-docs.atlassian.net/wiki/spaces/NAG8/pages/22250486)</span>*[.](https://infoblox-docs.atlassian.net/wiki/spaces/NAG8/pages/22250486)

   7. Save the configuration and click **Restart** if it appears at the top of the screen.