FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
zkarimov
Staff
Staff
Article Id 405626
Description This article describes the issue of custom admin profiles not having the same privileges as super admin profiles in FortiGate.
Scope FortiGate.
Solution

If a user can see accounts with higher privileges or broader access, it is considered a flaw in the system. Restricting custom admin profiles from viewing super_admin accounts is intentional and has been in place since v6.4.1.

 

  • Log in to the system using an administrator account:

 

admin-login-screen.png

 

  • Navigate to System -> Admin Profiles and select 'Create New'.

 

profiles.png

 

  • Create a new custom admin profile (e.g., 'custom_admin1') and set all permissions to Read/Write and select 'OK'.

 

custom_admin_profile_create.png

 

  • Navigate to System -> Administrators and select 'Create New' -> Administrator.

 

create-user-super-admin.png

 

  • For comparison, two administrator accounts will be created: one with the super_admin profile and one with the newly created custom admin profile (e.g., 'custom_admin1').
  • Create a new administrator user (e.g., 'superadmin2'), assign a password, and add it to the super_admin profile. Select 'OK'.

 

create-user-super-admin2.png

 

  • On the same Administrators page, create another administrator user (e.g., 'customadmin') and assign it to the newly created elevated custom admin profile (e.g., 'custom_admin1'). Select 'OK'.

 

create-user-custom-admin.png

 

  • Log out from the current administrator account and log back in using the newly created administrator account.
  • Navigate to System -> Administrators and check the list of administrator users. The complete list of administrators will be displayed.

 

logged-in-as-new-super-admin.png

 

  • Log out and log back in using the newly created custom administrator account credentials (e.g., 'customadmin').
  • Navigate to System -> Administrators and check the list of administrator users. Users with the super_admin profile will not be listed. Only accounts with similar privilege levels will be visible.

 

custom_admin_sees_only_it's_account.png

 

Related document:

Administrator profiles