How do I grant admin UI access to users in FusionAuth?
-
I'm trying to give a colleague access to the FusionAuth admin UI, but they're unable to log in even after I created a user account for them. I created the user in a custom tenant and registered them for an application, but login still fails with invalid credentials.
What's the correct way to grant admin UI access to additional users? Should the user be created in a specific tenant, and which application do they need to be registered to?
-
Now I have enough information to improve the answer. Let me create an enhanced version with documentation links.
To grant a user access to the FusionAuth admin UI, you need to:
- Create the user in the Default tenant (not a custom tenant)
- Register them for the FusionAuth application (the built-in admin application)
- Assign them an appropriate admin role during registration (e.g. "admin" for full access or a more limited role)
The key distinction is that the Tenant Manager Application is intended for granting third-party users limited admin access to manage users and identity providers within a specific tenant (this is an Enterprise feature). For full admin UI access, you must use the FusionAuth application in the Default tenant.
If the user's password setup email is being filtered as spam, you can set a temporary password manually and they'll be prompted to change it on first login.
Steps to add an admin user:
- Navigate to Users in the Default tenant
- Create a new user or select an existing one
- Go to the Registrations tab
- Click Add registration
- Select the FusionAuth application
- Choose the appropriate admin role from the dropdown
- Save the registration
Available Admin Roles
Here are the main admin UI roles you can assign:
Role Description adminCan manage everything, including creating new users with administrator privileges user_support_managerLimited scope — recommended for tier 1 support staff user_support_viewerCan view user information only user_managerCan add and edit users (note: this role has similar power to admin, so useuser_support_managerfor restricted access)user_deleterCan delete users Important: A user must have a registration in the FusionAuth application to access the admin UI — group membership alone is not sufficient.
Related Documentation
- FusionAuth Admin UI Roles - Complete list of admin roles and their capabilities
- User Support Guide - Detailed guide on creating admin users
- Default Tenant - Why the Default tenant cannot be deleted and its relationship to the FusionAuth application
- Tenant Manager Application - Enterprise feature for providing limited admin access to third-party users within specific tenants
-
D dan has marked this topic as solved
-
D dan moved this topic from Staged