You can use this form to create new roles and to assign roles to users. For each existing role, you can view the list of users assigned to it. If your system is integrated with Active Directory (AD), Microsoft Entra ID, or Active Directory Federation Services (AD FS), you can map the roles configured in Acumatica ERP to the groups configured in the Active Directory domain. For more information, see Managing User Access.
A role is a set of access rights to specific modules or other system entities. Some users are assigned only one role, while others are assigned multiple roles in accordance with different sets of employee responsibilities. For more information about roles, see Configuring User Roles.
A guest role is a role that you configure to give restricted access to the website and to only particular modules. Roles marked as guest roles can be associated with contact-related user types, which are intended for users who are external to the company, such as partners or contacts. For more information, see User Access: Linked Entities and User Types.
The form toolbar includes the buttons described below.
This area contains the summary elements of the role you are creating or viewing.
On this tab, you can view and update the list of users to whom the role selected (or entered, for a newly added role) in the Summary area is assigned.
The table toolbar has only standard buttons.
This tab provides information about Active Directory domain groups mapped to Acumatica ERP roles. The tab appears only if the Active Directory and Other External SSO feature is enabled on the Enable/Disable Features (CS100000) form and the integration of Acumatica ERP with Active Directory or Microsoft Entra ID has been enabled in the web.config file. For more information, see Integration with Active Directory and Integration with Microsoft Entra ID.
This tab provides information about claims specified during the integration of Acumatica ERP with Active Directory Federation Services (AD FS) which are mapped to Acumatica ERP roles. This tab appears only if the Active Directory and Other External SSO feature is enabled on the Enable/Disable Features (CS100000) form and the integration of Acumatica ERP with AD FS has been enabled in the web.config file. For more information, see Integration with AD FS.