Accounts can only be added to groups that belong to the same domain. Management Role Access Granted by Management Role Role Type UI-Account-Membership-Management Grants access to the user interfaces and workflows for viewing basic information about user accounts, as well as for initiating account group membership management workflows. Feature Set — Inherits the below Access Levels from the parent Management Role Definition: PAGES AND CONTROLS ACCESS Find Account Page Viewer for the page Account View One Page Viewer for the page Viewer for the General Tab Viewer for the Group Membership Grid Viewer for the Group Membership Changes Grid Viewer for the Resultant Membership Grid WORKFLOW ACCESS Add Accounts to Groups Initiator for the workflow Remove Service Principal from Groups Initiator for the workflow Update Account Group Membership Initiator for the workflow UI-Group-Membership-Management Grants people access to the user interfaces and workflows for viewing basic information about groups, as well as for initiating group membership management workflows. Feature Set — Inherits the below Access Levels from the parent Management Role Definition: PAGES AND CONTROLS ACCESS Find Group Page Viewer for the page Viewer for the Dashboard Tab Viewer for the All Groups Tab Viewer for the Groups I Manage Tab Group View One Page Viewer for the page Viewer for the General Tab Viewer for the Membership Changes Tab Viewer for the Group Members Grid WORKFLOW ACCESS Add Accounts to Groups Initiator for the workflow Update Group Account Membership Initiator for the workflow Add People to Groups Initiator for the workflow Update Person Group Membership Initiator for the workflow Temporary Group Membership Initiator for the workflow Add Groups to Group Initiator for the workflow Remove Groups from Group Initiator for the workflow Remove Service Principal from Groups Initiator for the workflow Active Directory User Accounts and Groups — In addition to the UI-Account-Membership-Management and UI-Group-Membership-Management Management Roles, users need the following roles to see manage Active Directory group membership for Active Directory user accounts VIS-Accounts-AD Grants visibility for all Active Directory user accounts. Visibility VIS-Groups-All-AD Grants visibility for all Active Directory groups. Visibility ACT-Account-Membership-Management-All-AD-Accounts Grants access to manage group membership for all Active Directory user accounts. If this role is not included, the change to group membership routes for approval to someone who can approve the request. Activity ACT-Group-Membership-Management-All-AD-Groups Grants access to manage group membership for all Active Directory groups. If this role is not included, the change to group membership routes for approval to someone who can approve the request. Activity AWS User Accounts and Groups — In addition to the UI-Account-Membership-Management and UI-Group-Membership-Management Management Roles, users need the following roles to manage AWS group memberships for AWS user accounts. VIS-Accounts-AWS Grants visibility for all AWS user accounts. Visibility VIS-Groups-All-AWS Grants visibility for all AWS groups. Visibility ACT-Account-Membership-Management-All Grants access to manage group membership for all user accounts, including AWS user accounts. If this role is not included, the change to group membership routes for approval to someone who can approve the request. Activity ACT-Group-Membership-Management-All-AWS-Groups Grants access to manage group membership for all AWS groups. If this role is not included, the change to group membership routes for approval to someone who can approve the request. Activity Linux User Accounts and Groups — In addition to the UI-Account-Membership-Management and UI-Group-Membership-Management Management Roles, users need the following roles to manage Linux group memberships for Linux user accounts VIS-Accounts-Linux Grants visibility for all Linux user accounts. Visibility VIS-Groups-All Grants visibility for all groups, including all groups in Linux systems. Visibility ACT-Account-Membership-Management-All Grants access to manage group membership for all user accounts, including Linux user accounts. If this role is not included, the change to group membership routes for approval to someone who can approve the request. Activity ACT-Group-Membership-Management-All-Groups Grants access to manage group membership for all groups, including Linux groups. If this role is not included, the change to group membership routes for approval to someone who can approve the request. Activity Local Windows User Accounts and Groups — In addition to the UI-Account-Membership-Management and UI-Group-Membership-Management Management Roles, users need the following roles to manage group memberships for Local Windows Server user accounts and groups VIS-Accounts-LocalWindows Grants visibility for all user accounts belonging to Local Windows Server account stores. Visibility VIS-Groups-All Grants visibility for all groups, including all groups in Local Windows Server account stores. Visibility ACT-Account-Membership-Management-All Grants access to manage group membership for all user accounts, including Local Windows user accounts. If this role is not included, the change to group membership routes for approval to someone who can approve the request. Activity ACT-Group-Membership-Management-All-Groups Grants access to manage group membership for all groups, including Local Windows groups. If this role is not included, the change to group membership routes for approval to someone who can approve the request. Activity Office 365 User Accounts and Groups — In addition to the UI-Account-Membership-Management and UI-Group-Membership-Management Management Roles, users need the following roles to manage group memberships for Office 365 user accounts and groups VIS-Accounts-O365 Grants visibility for all Office 365 / Azure AD user accounts. Visibility VIS-Groups-All-O365 Grants visibility for all Office 365 groups. Visibility ACT-Account-Membership-Management-All Grants access to manage group membership for all user accounts, including Office 365 / Azure AD user accounts. If this role is not included, the change to group membership routes for approval to someone who can approve the request. Activity ACT-Group-Membership-Management-All-O365-Groups Grants access to manage group membership for all Office 365 groups. If this role is not included, the change to group membership routes for approval to someone who can approve the request. Activity SAP User Accounts and Groups — In addition to the UI-Account-Membership-Management and UI-Group-Membership-Management Management Roles, users need the following roles to manage group memberships for SAP user accounts and groups VIS-Accounts-SAP Grants visibility for all SAP user accounts. Visibility VIS-Groups-All-SAP Grants visibility for all Office 365 groups. Visibility ACT-Account-Membership-Management-All-SAP-Accounts Grants access to manage group membership for all SAP and ABAP user accounts. If this role is not included, the change to group membership routes for approval to someone who can approve the request. Activity ACT-Group-Membership-Management-All-SAP-Groups Grants access to manage membership for all SAP Roles and Profiles. If this role is not included, the change to group membership routes for approval to someone who can approve the request. Activity