Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Feature Request]: More Granular account permissions #1931

Closed
bonlewy opened this issue Dec 1, 2023 · 3 comments
Closed

[Feature Request]: More Granular account permissions #1931

bonlewy opened this issue Dec 1, 2023 · 3 comments
Labels
enhancement New feature or request no-priority

Comments

@bonlewy
Copy link

bonlewy commented Dec 1, 2023

Description of the new feature - must be an in-depth explanation of the feature you want, reasoning why, and the added benefits for MSPs as a whole.

We would like to add some more staff members to our CIPP platform, but, we dont want them to be able to do everything, such as not allowing access to:

  • Transport Rules
  • Intune
  • Defender
  • Anything under CIPP Settings
  • Tenant Administration

Our CIPP instance is hosted so all we are able to currently do is add a user to the portal as Admin, Edit or Read Only. If we could add someone and then select what they can view, this would be great to then enrol 1st Line engineers into the portal

PowerShell commands you would normally use to achieve above request

No response

@bonlewy bonlewy added enhancement New feature or request no-priority labels Dec 1, 2023
@KelvinTegelaar
Copy link
Owner

This has been discussed at length in other feature requests:: we're not planning on adding this as this would out on undue burden of maintaining a security system on us. We want to prevent being blamed for security failures that happen because a msp doesnt understand the complex setup or makes a mistake.

However you can check out docs for custom roles, which shifts this burden entirely to the msp themselves to maintain:

https://docs.cipp.app/setup/installation/roles

@bonlewy
Copy link
Author

bonlewy commented Dec 1, 2023

This has been discussed at length in other feature requests:: we're not planning on adding this as this would out on undue burden of maintaining a security system on us. We want to prevent being blamed for security failures that happen because a msp doesnt understand the complex setup or makes a mistake.

However you can check out docs for custom roles, which shifts this burden entirely to the msp themselves to maintain:

https://docs.cipp.app/setup/installation/roles

Im not sure from looking at this that it is possible to do it on the hosted platform, only if self-hosted on Azure?

@KelvinTegelaar
Copy link
Owner

As it says at the bottom:

If you are a hosted client, Custom Roles are supported by sending your configuration file to our helpdesk. :)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
enhancement New feature or request no-priority
Projects
None yet
Development

No branches or pull requests

2 participants