Control user access by creating and changing permission sets from the Permission Sets page.
You can also copy and delete permission sets from the Permission Sets page.
Open the Permission Sets page: select Menu → User Management → Permission Sets.
Select one of these actions.
Add a permission set:
Click New Permission Set.
Type a unique name for the new permission set.
To immediately assign specific users to this permission set, select their user names in the Users section.
To map any Active Directory or Entra ID groups to this permission set, select the server from the Server Name list, then click Add.
If you added any Active Directory servers that you want to remove, select them in the Active Directory list box, then click Remove.
The XML file contains only roles with a defined level of permissions. If, for example, a Permission Set has no permissions for queries and reports, no entry appears in the file.
Edit a permission set:
Select a permission set to change.
Type a unique name for the new permission set.
To immediately assign specific users to this permission set, select their user names in the Users section.
To map any Active Directory groups to this permission set, select the server from the Server Name list, then click Add.
If you added any Active Directory servers that you want to remove, select them in the Active Directory list box, then click Remove.
Enable tag permissions for non-administrator users
Perform these steps to prevent authorization errors when non-administrator users run the System.Find command. This is required after you upgrade to ePO - On-prem 5.10.x Service Pack 1 Update 6.
Select the permission set assigned to the non-administrator users.
In the list of categories, click Edit next to the Systems category.
Locate the Tag use section.
Select the Apply, exclude, and clear tags checkbox.
Click Save.
Note
Affected users must log off and log on again for these changes to take effect. For more information, see KB15218.