(/content/techdocs/en_US.
html)
Updated on Thu Mar 13 [Link] UTC 2025
Home (/) | Panorama (/content/techdocs/en_US/[Link])
| Panorama Administrator's Guide (/content/techdocs/en_US/panorama/10-1/[Link])
| Set Up Panorama (/content/techdocs/en_US/panorama/10-1/panorama-admin/[Link])
| Set Up Administrative Access to Panorama (/content/techdocs/en_US/panorama/10-1/panorama-admin/set-up-panorama/set-up-
[Link])
| Configure an Admin Role Profile (/content/techdocs/en_US/panorama/10-1/panorama-admin/set-up-panorama/set-up-administrative-
access-to-panorama/[Link])
DOWNLOAD PDF (/CONTENT/DAM/TECHDOCS/EN_US/PDF/PANORAMA/10-1/PANORAMA-ADMIN/PANORAMA-
[Link])
Panorama Administrator's Guide
(/content/techdocs/en_US/panorama/10-
1/[Link])
Configure an Admin Role Profile
Table of Contents
Admin Role profiles are custom Administrative Roles (/content/techdocs/en_US/panorama/10-1/panorama-
admin/panorama-overview/role-based-access-control/[Link]#id93822266-c46a-482c-a128-
ee3c0e89b4a4) that enable you to define granular administrative access privileges to ensure protection for sensitive
company information and privacy for end users. As a best practice, create Admin Role profiles that allow administrators to
access only the areas of the management interfaces required to perform their jobs.
STEP 1 -
Select Device > Admin Roles and select the Template in which to configure a firewall admin role profile
([Link]
administrators/[Link]).
You must create an Admin Role profile on the firewall and assign it to the Panorama management server Admin
Role profile to allow administrators to context switch (/content/techdocs/en_US/panorama/10-1/panorama-
admin/panorama-overview/centralized-firewall-configuration-and-update-management/context-
[Link]#id44fd7efe-a4b1-4e9e-8ec9-9bafb2c3fa63) between Panorama and
managed firewall web interfaces.
STEP 2 -
Select Panorama > Admin Roles and click Add.
STEP 3 -
Enter a Name for the profile and select the Role type: Panorama or Device Group and Template.
This site usesSTEP
cookies4essential
- to its operation, for analytics, and for personalized content and ads. By
continuing toConfigure
browse thisaccess
site, you acknowledge
privileges the use
to each of cookies.
functional Privacy
area statement ❯ Cookie Settings
([Link]
([Link]
admin/firewall-administration/reference-web-interface-administrator-access) of Panorama (Web UI) by
toggling the icons to the desired setting: Enable (read-write), Read Only, or Disable.
If administrators with custom roles will commit device group or template changes to man-
aged firewalls, you must give those roles read-write access to Panorama > Device Groups
and Panorama > Templates. If you upgrade from an earlier Panorama version, the upgrade
process provides read-only access to those nodes.
STEP 5 -
If the Role type is Panorama, configure access to the XML API by toggling the Enabled/Disabled icon for each
functional area.
STEP 6 -
If the Role type is Panorama, select an access level for the Command Line interface: None (default), superuser,
superreader, or panorama-admin.
STEP 7 -
( Optional ) To allow Panorama administrators to Context Switch between the Panorama and firewall web
interface, enter the name of Device Admin Role you configured in Step 1.
STEP 8 -
Click OK to save the profile.
Was this information helpful?
Yes No
Previous Next
(/content/techdocs/en_US/panorama/10- (/content/techdocs/en_US/panorama/10-
Set Up Configure
1/panorama-admin/set-up-panorama/set- 1/panorama-admin/set-up-panorama/set-up-
Administrative an
up-administrative-access-to- administrative-access-to-
Access to Access
[Link]) panorama/[Link])
Panorama Domain
Technical Documentation Co
Release Notes (/content/techdocs/en_US/[Link]) Abo
Search (/content/techdocs/en_US/[Link]) Care
Blog ([Link] Cus
documentation/) LIVE
Compatibility Matrix (/content/techdocs/en_US/compatibility- Kno
[Link])
OSS Listings (/content/techdocs/en_US/[Link])
Sitemap (/content/techdocs/en_US/[Link])
([Link] ([Link]
([Link]
This site uses cookies essential to its operation, for analytics, and for personalized content and ads. By
(/content/techdocs/en_US.html)
continuing to browse this site, you acknowledge the use of cookies. Privacy statement ❯ © 2025 Palo Alto Ne
([Link]