Found this content helpful? Log in or sign up to leave a like!
Subaccount Admin Permissions Advice
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hello,
This is the first time in 5 years that I am creating a subaccount admin role and wanted advice from others. The default subaccount admin role has all permissions enabled. I've gone through all the permissions and although I know everyone's needs are different, are there any permissions that would suggest them not having? Any permissions that you would suggest I look over closely?
They need to be able to:
- create courses
- copy courses
- assign user roles and permissions
- provide support for that departments users
- manage LTIs
Thanks for any advice!
Debbie
Solved! Go to Solution.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hello @olguin - below are the permissions that I would not enable -
- Account-level settings - manage
- Data Services - manage
- Storage Quotas - manage (We do not change this - everyone gets 500MB. We ask for OneDrive be used for Files and Studio/ Stream for media content (i.e., larger files))
I recommend creation of guidelines ahead of enabling 'Admins - add/remove' and 'Permissions - manage'. For certain, everyone would need to be on the same page with assigning permissions. To share, we follow the least access privilege model which is partly explained here:
- Restricting access: Users and processes should only have access to the data, resources, and functionalities they need to perform their designated roles.
- Just-in-time privileges: Elevated privileges should be granted only when and for as long as they are required, then revoked.
- Separation of duties: Tasks should be separated and performed by different individuals with distinct roles, further limiting access.
- Auditing and monitoring: Regularly audit and monitor admin access to ensure compliance and identify potential issues.
I would also implement a shared change log where all subaccount admins documented notable changes to the LMS. For example, installation of an LTI to the subaccount, system settings changes, etc.
References:
https://csrc.nist.gov/glossary/term/least_privilege
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi @olguin,
For our subaccount admin role, we have the following permissions disabled:
- Admins - add / remove
- Data Services - manage
- Developer Keys - manage
- Impact - Manage
- Manage Account Calendars
- Manage LTI
- Reset Multi-Factor Authentication
- SIS Data - import
- Storage Quotas - manage
- Users - Manage Access Tokens
In addition, we have the following permissions disabled for "official" SIS course subaccounts
- Users - Students
- Users - Teachers
As you said, everyone's wants and needs will probably be a little different here, but hopefully you'll have a shorter list of things to consider from the posts here.
-Chris