Elevated privilege roles
Summarize
Summary of Elevated Privilege Roles
Elevated privilege roles require users to manually accept the responsibility of using these roles before accessing their features. By default, users do not have elevated privileges upon login and must elevate their role for the duration of their session, which ends with session timeout or logout.
Show less
Key Features
- Any role can be designated as an elevated privilege role, allowing assignment to multiple users to manage access rights effectively.
- Users must meet specific conditions to use an elevated role, including having the role assigned and manually elevating to the required role for its privileges.
- The admin role can only be granted by another user with the admin role, while the securityadmin role requires elevation by a user with the admin role.
- The securityadmin role is the sole elevated privilege role in the base system, granting access to ACLs and High Security Settings.
- A property exists to require admins to manually select their elevated role, enhancing security management.
Key Outcomes
By effectively managing elevated privilege roles, ServiceNow customers can ensure that users only access necessary rights when needed, thereby enhancing security and compliance. Administrators will have the tools to control user access more rigorously, ensuring that elevated privileges are handled safely and responsibly.
Elevated privilege roles require you to manually accept the responsibility of using the role before you can access the features of the role.
By default, you do not have elevated privilege roles upon login. You must manually elevate to the privilege of the role. An elevated privilege role lasts only for the duration of your user session. Session timeout or logout removes the role.
You can designate any role as an elevated privilege role, and then assign that role to one or more users. Do this when you want to restrict users from having access to the rights that the role provides immediately after login. You can designate the privilege role on the Role form. See Create a role for instructions.
- The elevated role must be assigned to you.
- You must manually elevate to a specific elevated role to get its privileges, even if you are
already elevated to a second elevated role that contains the first elevated role.
For example, if elevated role A contains elevated role B, even if you elevate to role A, you must still elevate to role B to get its privileges.
The admin role
- Non-admin users cannot add a user to a group that contains the admin role.
- To grant the security_admin role to a user, the granting user must also have the admin role and must elevate to the security_admin role before granting the security_admin role to other users. A user with only the admin role cannot grant the security_admin role to other users.
- A user without the security_admin role cannot add a user to a group that contains the security_admin role.
The security_admin role
In the base system, the security_admin role is the only role that has elevated privileges. This role is automatically assigned to the user who is the default System Administrator (admin) user. It provides access to ACLs and High Security Settings.