UMX - User management by local administrators
We have local administrators who are able to add and maintain users and assign responsibilities to the users.
We want to use User Management for creating users and assigning roles/responsibilities to them. Howere the User Management responsibility does also allow eg. creating roles, etc. We don't want the local administrators to have access to this functionality.
So we created a new role with a new responsibility for these local administrators and assigns to the role the permissions of Create, Inactivate, Reactivate User Account, Update Username, Edit Person Details, Reset Password, Query Person Details and Assign/Revoke Role. (Defining Delegated Administration Privileges for Roles in User Guide