FortiClient
FortiClient proactively defends against advanced attacks. Its tight integration with the Security Fabric enables policy-based automation to contain threats and control outbreaks. FortiClient is compatible with Fabric-Ready partners to further strengthen enterprises’ security posture.
btan
Staff & Editor
Staff & Editor
Article Id 420066
Description This article describes how to configure the bare minimum admin permission to send the Invitation Code email in FortiClient EMS.
Scope FortiClient EMS v7.2 and v7.4.
Solution

The goal is to create an admin role that can send an Invitation Code email while restricting all other operational functions in FortiClient EMS.

 

  • Clone the default 'Restricted Administrator' role, tick 'View User Configuration ' -> Save.

 

2give-permission.png

 

  • The user who got assigned to this role will be able to see the 'Send' Invitation Code button.

 

4can-send.png

 

  • However, there will be a 'Permission Denied' pop-up message, and FortiClient EMS will log out users.

 

kb-nov-1-2.png

 

Solution:

  1. Edit the admin role with below permissions:
    Manage Invitations + View User Configurations + Manage alert settings + View alert settings.

    kb-nov-1-3.png
  2. Assign the role to the admin user.
                                                           
    3assign-role.png                                                         
  3. The admin user logs into FortiClient EMS, attempts to send the Invitation Code email.
    It is now possible to send the Invitation Code email without getting the 'Permission Denied' pop-up message.
                                                                           
    kb-nov-1-1.png                                                          
  4. In cases where the pop-up message still appears, simply select 'Cancel'.
    The page will not refresh, and the Invitation Code email will still be sent.
                                                                           
    kb-nov-1-4.png

 

Contributors