•  Refresh
  • Tools
  •  
  • Expand All
  • Collapse All
  • Locales
  • Get File Link
  • Report Typo
  • Print
  • Export

User Roles

Form ID: (SM201005)

You can use this form to create new roles and to assign roles to users. For each existing role, you can view the list of users assigned to it. If your system is integrated with Active Directory (AD), Microsoft Entra ID, or Active Directory Federation Services (AD FS), you can map the roles configured in Acumatica ERP to the groups configured in the Active Directory domain. For more information, see Managing User Access.

A role is a set of access rights to specific modules or other system entities. Some users are assigned only one role, while others are assigned multiple roles in accordance with different sets of employee responsibilities. For more information about roles, see Configuring User Roles.

A guest role is a role that you configure to give restricted access to the website and to only particular modules. Roles marked as guest roles can be associated with contact-related user types, which are intended for users who are external to the company, such as partners or contacts. For more information, see User Access: Linked Entities and User Types.

Back to TopForm Toolbar

The form toolbar includes the buttons described below.

Button Description
Reload AD Groups Updates the list of user groups in Acumatica ERP with current information from AD. This button appears only if the Active Directory and Other External SSO feature is enabled on the Enable/Disable Features (CS100000) form and you integrated Acumatica ERP instance with AD or Entra ID, and when the number of users in AD or Entra ID is greater than or equal to 1000.

Back to TopSummary Area

This area contains the summary elements of the role you are creating or viewing.

Element Description
Role Name The unique identifier of the role. Type the name of the new role, or select a role from the list of available roles.
Role Description A detailed description of the role.
Guest Role A check box that you select to indicate that the selected role is a guest role.

Back to TopMembership Tab

On this tab, you can view and update the list of users to whom the role selected (or entered, for a newly added role) in the Summary area is assigned.

The table toolbar has only standard buttons.

Table Columns

Column Description
Username The login name of the user to whom this role is assigned.
Display Name The combination of the First Name and Last Name on the Users (SM201010) form of the user selected in the Username column.
Status The current status of the selected user (Active, Online, Disabled, Temporarily Locked).
Comment Any comment that was provided for the selected user on the Users (SM201010) form.
Domain The domain the user belongs to. This column appears if integration with Active Directory is enabled.
Inherited A check box that shows (if selected) that the roles assigned to the user are defined by the AD group the user belongs to. If the check box is cleared, the roles were assigned specifically to the user. This column appears if integration with Active Directory is enabled.

Back to TopActive Directory Tab

This tab provides information about Active Directory domain groups mapped to Acumatica ERP roles. The tab appears only if the Active Directory and Other External SSO feature is enabled on the Enable/Disable Features (CS100000) form and the integration of Acumatica ERP with Active Directory or Microsoft Entra ID has been enabled in the web.config file. For more information, see Integration with Active Directory and Integration with Microsoft Entra ID.

The table toolbar has only standard buttons.

Table Columns

Column Description
Group The name of the domain group mapped to the role selected in the summary area.
Domain The domain with which Acumatica ERP is integrated.
Description A more detailed description of the domain group from Active Directory.

Back to TopClaims Tab

This tab provides information about claims specified during the integration of Acumatica ERP with Active Directory Federation Services (AD FS) which are mapped to Acumatica ERP roles. This tab appears only if the Active Directory and Other External SSO feature is enabled on the Enable/Disable Features (CS100000) form and the integration of Acumatica ERP with AD FS has been enabled in the web.config file. For more information, see Integration with AD FS.

The table toolbar has only standard buttons.

Table Columns

Column Description
Group The name of the domain group mapped to the role selected in the summary area. You must use the following format to enter the domain groups: <Domain>\<Domain Group>.

Back to TopRelated Articles