IAM Admin access to the IAM Web UI allows the user to perform most system administration tasks. The role grants full access to the IAM organization security policies, user access controls, and user deployment.
Note
IAM Admin is a global role, and it cannot be modified or deleted.
Unlike the Trellix Super Admin role, the IAM Admin role does not grant visibility or access to OIDC clients, IAM audit events, or other IAM organizations.
Viewing the roles and entitlements
To view the entitlements assigned to the role, filter the list of roles to show only IAM Web UI roles, and then drill down from the IAM Admin role to its component entitlements.
Requirements
To view the entitlements associated with the IAM Admin role:
Log in to the IAM Web UI.
Select Organization Settings > Roles. The Roles page lists the IAM global roles and custom roles in your IAM organization.
Filter the list on the Description column, specifying the match string
IAMin all uppercase letters. (The filter is case-sensitive.) The list refreshes and shows only the roles that grant access to the IAM Web UI.
Click IAM Admin in the Name column.
The Assigned Entitlements panel lists the entitlements assigned to the role.
