Difference between revisions of "Super Admin"

From Studentnet Wiki
Jump to navigation Jump to search
Line 1: Line 1:
Super Admins have full permissions on every feature within the Dashboard. Organisational unit restrictions on granted permissions do not apply to this role. This role overrides all other roles, members of super admin have access to everything regardless of what other roles are in place
+
==Super Admin==
 +
Super Admin is a special role in Admin role. Super Admin has full permissions for all users and features within the dashboard.
 +
The use of Super Admin should not be used or given without careful consideration.
 +
 
 +
Some best practices for using/giving Super Admin privileges:
 +
*Do not use Super Admin for daily use
 +
*Super Admins must have a separate account for daily use
 +
*Give to limited users
 +
*Must have MFA enabled for users with Super Admin role
 +
 
 +
===Do not use for daily use===
 +
Super Admin accounts should not be used for daily use, Super Admin accounts should only be used when specific task requiring Super Admin privileges are required.
 +
This is to reduce the risk of accidental changes that may occur with daily usage of an administrator account.
 +
 
 +
===Super Admins should have a separate account for daily use===
 +
Since Super Admin accounts should not be used for daily use, a Non-Super Admin account should be created for daily use.
 +
This limits the risk of accidental changes that may occur with daily use of an administrator account.
 +
 
 +
===Give to limited users===
 +
Due to the nature of the Super Admin role, it is best to give the Super Admin privileges to a select few users.
 +
This reduces the number of potential breaches for your school's dashboard.
 +
 
 +
===Must have MFA enabled for users with Super Admin role===
 +
Since having a compromised Super Admin account would leave your entire school's dashboard vulnerable.
 +
To reduce the risk of having a Super Admin account compromised, having MFA enabled adds an extra layer of security for the Super Admin account.
 +
 
  
 
[[Category:Admin Roles]]
 
[[Category:Admin Roles]]

Revision as of 02:18, 4 February 2020

Super Admin

Super Admin is a special role in Admin role. Super Admin has full permissions for all users and features within the dashboard. The use of Super Admin should not be used or given without careful consideration.

Some best practices for using/giving Super Admin privileges:

  • Do not use Super Admin for daily use
  • Super Admins must have a separate account for daily use
  • Give to limited users
  • Must have MFA enabled for users with Super Admin role

Do not use for daily use

Super Admin accounts should not be used for daily use, Super Admin accounts should only be used when specific task requiring Super Admin privileges are required. This is to reduce the risk of accidental changes that may occur with daily usage of an administrator account.

Super Admins should have a separate account for daily use

Since Super Admin accounts should not be used for daily use, a Non-Super Admin account should be created for daily use. This limits the risk of accidental changes that may occur with daily use of an administrator account.

Give to limited users

Due to the nature of the Super Admin role, it is best to give the Super Admin privileges to a select few users. This reduces the number of potential breaches for your school's dashboard.

Must have MFA enabled for users with Super Admin role

Since having a compromised Super Admin account would leave your entire school's dashboard vulnerable. To reduce the risk of having a Super Admin account compromised, having MFA enabled adds an extra layer of security for the Super Admin account.