---
title: "About Admin Groups"
canonical: "https://docs.infoblox.com/space/nios90/280275587/About%20Admin%20Groups"
format: markdown
---
All administrators must belong to an admin group. The permissions and properties that you set for a group apply to all administrators assigned to that group. You can assign a dashboard template to an admin group. A dashboard template specifies the tasks an admin group can access through the **Tasks** **Dashboard** tab when they log in to Grid Manager. For information about dashboard templates, see <span style="color: #0000ff">*[Configuring Dashboard Templates](https://infoblox-docs.atlassian.net/wiki/spaces/nios90/pages/280401437)*</span>. You can also restrict certain user groups to manage specific tasks in the **Tasks** **Dashboard** tab only. These users cannot manage other core network services through Grid Manager. For information about how to apply this restriction, see <span style="color: #003366">Limited-Access Admin Groups below</span>.  
  
To define admins who can perform specific core network service tasks, you can set up admin groups and assign them permissions for those tasks. To control when and whether certain tasks should be performed, you can add an admin group to an approval workflow and define the admins as submitters or approvers. A submitter is an admin whose tasks require approvals before execution, and an approver is an admin who can approve the submitted tasks. When you add submitter and approver groups to an approval workflow, you have control over who can perform which mission critical tasks and whether and when the tasks should be executed. For more information about how to create and configure approval workflows, see <span style="color: #0000ff">*[Configuring](https://infoblox-docs.atlassian.net/wiki/spaces/nios90/pages/280398484)*</span>[ ](https://infoblox-docs.atlassian.net/wiki/spaces/nios90/pages/280398484)<span style="color: #0000ff">*[Approval](https://infoblox-docs.atlassian.net/wiki/spaces/nios90/pages/280398484)*</span>[ ](https://infoblox-docs.atlassian.net/wiki/spaces/nios90/pages/280398484)<span style="color: #0000ff">*[Workflows](https://infoblox-docs.atlassian.net/wiki/spaces/nios90/pages/280398484)*</span>.  
  
There are three types of admin groups:

- **Superuser** – Superuser admin groups provide their members with unlimited access and control of all the operations that a NIOS appliance performs. There is a default superuser admin group, called **admin-group**, with one superuser administrator, **admin**. You can add users to this default admin group and create additional admin groups with superuser privileges. Superusers can access the appliance through its console, GUI, and API. In addition, only superusers can create admin groups.
- **Limited-Access** – Limited-access admin groups provide their members with read-only or read/write access to specific resources. These admin groups can access the appliance through the GUI, API, or CLI. They cannot access the appliance through the console.
- **Default** – When upgrading from previous NIOS releases, the appliance converts the ALL USERS group to the Default Group when the ALL USERS Group contains admin accounts. The appliance does not create the Default Group if there is no permission in the ALL USERS group. The permissions associated with the ALL USERS group are moved to a newly created role called Default Role. Supported in previous NIOS releases, the ALL USERS group was a default group in which you defined global permissions for all limited-access users. This group implicitly included all limited-access users configured on the appliance.

All limited-access admin groups require either read-only or read/write permission to access certain resources, such as Grid members, and DNS and DHCP resources, to perform certain tasks. Therefore, when you create an admin group, you must specify which resources the group is authorized to access and their level of access.  
  
Only superusers can create admin groups and define their administrative permissions. There are two ways to define the permissions of an admin group. You can create an admin group and assign permissions directly to the group, or you can create roles that contain permissions and assign the roles to an admin group.  
  
You must create admin groups and assign them access to the cloud API and applicable permissions so they have authority over delegated objects. When you assign permissions for objects that have not been delegated, these admin groups or admin users assume applicable permissions to these un-delegated objects. For example, you can create an admin group that can access a specific set of networks while another can access another set of networks. Note that you cannot create a new admin group using the same name. For information about Cloud Network Automation, see <span style="color: #0000ff">*[Deploying](https://infoblox-docs.atlassian.net/wiki/spaces/nios90/pages/280758966)*</span>[ ](https://infoblox-docs.atlassian.net/wiki/spaces/nios90/pages/280758966)<span style="color: #0000ff">*[Cloud](https://infoblox-docs.atlassian.net/wiki/spaces/nios90/pages/280758966)*</span>[ ](https://infoblox-docs.atlassian.net/wiki/spaces/nios90/pages/280758966)<span style="color: #0000ff">*[Network](https://infoblox-docs.atlassian.net/wiki/spaces/nios90/pages/280758966)*</span>[ ](https://infoblox-docs.atlassian.net/wiki/spaces/nios90/pages/280758966)<span style="color: #0000ff">*[Automation](https://infoblox-docs.atlassian.net/wiki/spaces/nios90/pages/280758966)*</span>.  
  
Complete the following tasks to assign permissions directly to an admin group:

1. Create an admin group, as described in [Creating Limited-Access Admin Groups](https://infoblox-docs.atlassian.net/wiki/spaces/nios90/pages/1471316391).
2. Assign permissions to the admin group, as described in <span style="color: #0000ff">*[About](https://infoblox-docs.atlassian.net/wiki/spaces/nios90/pages/280275424)*</span>[ ](https://infoblox-docs.atlassian.net/wiki/spaces/nios90/pages/280275424)<span style="color: #0000ff">*[Administrative](https://infoblox-docs.atlassian.net/wiki/spaces/nios90/pages/280275424)*</span>[ ](https://infoblox-docs.atlassian.net/wiki/spaces/nios90/pages/280275424)<span style="color: #0000ff">*[Permissions](https://infoblox-docs.atlassian.net/wiki/spaces/nios90/pages/280275424)*</span>[.](https://infoblox-docs.atlassian.net/wiki/spaces/nios90/pages/280275424) Complete these tasks to assign admin roles to an admin group:
3. Create an admin role, as described in <span style="color: #0000ff">*[About](https://infoblox-docs.atlassian.net/wiki/spaces/nios90/pages/280668617)*</span>[ ](https://infoblox-docs.atlassian.net/wiki/spaces/nios90/pages/280668617)<span style="color: #0000ff">*[Admin](https://infoblox-docs.atlassian.net/wiki/spaces/nios90/pages/280668617)*</span>[ ](https://infoblox-docs.atlassian.net/wiki/spaces/nios90/pages/280668617)<span style="color: #0000ff">*[Roles](https://infoblox-docs.atlassian.net/wiki/spaces/nios90/pages/280668617)*</span>.
4. Define permissions for the newly created admin role, as described in [Creating-Admin-Roles](https://docs.infoblox.com/space/nios90/280668617/About+Admin+Roles#Creating-Admin-Roles)<span style="color: #003366">, </span>see <span style="color: #0000ff">*[About](https://infoblox-docs.atlassian.net/wiki/spaces/nios90/pages/280668617)*</span>[ ](https://infoblox-docs.atlassian.net/wiki/spaces/nios90/pages/280668617)<span style="color: #0000ff">*[Admin](https://infoblox-docs.atlassian.net/wiki/spaces/nios90/pages/280668617)*</span>[ ](https://infoblox-docs.atlassian.net/wiki/spaces/nios90/pages/280668617)<span style="color: #0000ff">*[Roles](https://infoblox-docs.atlassian.net/wiki/spaces/nios90/pages/280668617)*</span>.
5. Create an admin group and assign the role to the group, as described in [Creating Limited-Access Admin Groups](https://docs.infoblox.com/space/nios90/1471316391/Creating+Limited-Access+Admin+Groups).

After you have created admin groups and defined their administrative permissions, you can assign administrators to the group.

- For local admins, see <span style="color: #0000ff">*[Creating](https://infoblox-docs.atlassian.net/wiki/spaces/nios90/pages/280766011)*</span>[ ](https://infoblox-docs.atlassian.net/wiki/spaces/nios90/pages/280766011)<span style="color: #0000ff">*[Local](https://infoblox-docs.atlassian.net/wiki/spaces/nios90/pages/280766011)*</span>[ ](https://infoblox-docs.atlassian.net/wiki/spaces/nios90/pages/280766011)<span style="color: #0000ff">*[Admins](https://infoblox-docs.atlassian.net/wiki/spaces/nios90/pages/280766011)*</span>[.](https://infoblox-docs.atlassian.net/wiki/spaces/nios90/pages/280766011)
- For remote admins, see <span style="color: #0000ff">*[About](https://infoblox-docs.atlassian.net/wiki/spaces/nios90/pages/412976519)*</span>[ ](https://infoblox-docs.atlassian.net/wiki/spaces/nios90/pages/412976519)<span style="color: #0000ff">*[Remote](https://infoblox-docs.atlassian.net/wiki/spaces/nios90/pages/412976519)*</span>[ ](https://infoblox-docs.atlassian.net/wiki/spaces/nios90/pages/412976519)<span style="color: #0000ff">*[Admins](https://infoblox-docs.atlassian.net/wiki/spaces/nios90/pages/412976519)*</span>.