Users assigned the api_admin role have no access to Endpoint Security (HX) appliance functionality via the Web UI. They have basic and extended API authorization for Endpoint Security (HX) appliance features. The extended authorization allows them to maintain custom policy channels and to contain hosts. (Custom policy channels can be used to distribute custom configuration files to agents running on hosts in specified host sets.)
API Administrators cannot run CLI commands or change their passwords. An Endpoint Security (HX) appliance administrator (user role Admin) must change their passwords, if necessary.
See the Endpoint Security (HX) REST API Guide.