Moving clients to roles

Super Administrators can use the Move Client To Role page to move one or more clients to a delegated administration role. Once a client has been moved, that client appears in the Managed Clients list and on the Clients page in the target role.

  • The policy applied to the client in the Super Administrators role and the filters that it enforces are copied to the delegated administration role.
  • Delegated administrators can change the policies applied to their managed clients.
  • Filter Lock restrictions do not affect clients managed by Super Administrators, but do affect managed clients in delegated administration roles.
  • If a group or OU is added to a role as a managed client, delegated administrators in that role can assign policies to individual users in the group or OU.
  • If a network (IP address range) is added to a role as a managed client, delegated administrators in that role can assign policies to individual computers in that network.
  • The same client cannot be moved to multiple roles.
To move the selected clients to a delegated administration role:
  1. Use the Select role drop-down list to select a destination role.
  2. Click OK

    A popup message indicates that the selected clients are being moved. The move process may take a while.

  3. Changes are not implemented until you click Save and Deploy.

If delegated administrators in the selected role are logged on with policy access during the move process, they will have to log out of the Forcepoint Security Manager and log on again to see the new clients in their Managed Clients list.