[GF#6] Read-Only Admin

GlideFather
Tera Patron

Not a question. 

Discover how read-only admin access in ServiceNow lets you share full platform visibility without risk.

 

GlideFather_0-1768432855880.png
GlideFather_1-1768432860640.png
GlideFather_2-1768432864683.png

GlideFather_3-1768432870212.png

 

Have you ever needed read-only admin?

_____
Answers generated by GlideFather. Check for accuracy.

4 REPLIES 4

SebinS
Tera Contributor

Thankyou for information.

EgSnow
Tera Contributor

This situation can only be bypassed if the user admin and read-only roles impersonate a user with admin privileges. In that case, the user admin and read-only would effectively become a full admin.

Ahoy @EgSnow,

 

thank you for your comment, I am quite not sure I understand you but it seems that you claim that user_admin and read_only will allow you to get full admin rights by impersonation. Is that what you are saying? Because it is not correct and I validated that, see below.

 

In principal, you cannot impersonate for higher role than you have assigned yourself, it is a security measure.

 

You mentioned user_admin - I created a dummy user with that role, assigned it also itil to access backend and impersonator role to be able impersonating.

 

See on the left, dummy user with 3 roles (+ auto-inherited many more), then I created credentials for them to login locally for that user and tried to impersonate for an admin - not possible:

 

GlideFather_0-1778224781163.png

 

But an admin can impersonate for another admin - OK:

GlideFather_1-1778224864072.png

 

Is that what you meant or could you possibly elaborate a bit more on what you wanted to say?

_____
Answers generated by GlideFather. Check for accuracy.

Hello Tera Patron,

I’d like to clarify my use case once more.

User_a has both "admin" and "snc_read_only" roles, while User_b only has the "admin" role.

When User_a impersonates User_b, User_a is granted writing permissions.

I hope this explanation helps clarify the scenario. So, there is a little risk.

Kind Regards