# Preventing group admins from accessing system-wide settings

**URL:** https://community.passbolt.com/t/preventing-group-admins-from-accessing-system-wide-settings/7141
**Category:** Community Feedback
**Created:** [April 19, 2023, 10:31am UTC](https://community.passbolt.com/t/preventing-group-admins-from-accessing-system-wide-settings/7141 "2023-04-19T10:31:41Z")
**Posts on this page:** 3
**Page:** 1

<div class="post-metadata">

### Author: ![schester](https://avatars.discourse-cdn.com/v4/letter/s/ecb155/32.png) [@schester](https://community.passbolt.com/u/schester)
#### Post date: [April 19, 2023, 10:31am UTC](https://community.passbolt.com/t/preventing-group-admins-from-accessing-system-wide-settings/7141/1 "2023-04-19T10:31:41Z")

</div>

My company has been using Passbolt for a couple of years, and we’re considering an upgrade but…

It looks like there are only 2 levels of access to Passbolt: ‘admin’ or ‘user’. Most of our users have ‘user’ access, but some people need to be able to create groups and assign group managers, so they have ‘admin’ access.

However, I’ve just realised that making a person an ‘admin’ gives rights to access and change system-wide settings, such as MFA, Single Sign-on etc. This is horrifying to me!

Have I misunderstood something? Is there a way to give people basic rights to administer groups, without letting them see or change really significant system-wide settings?

---

<div class="post-metadata">

### Author: ![clayton](https://avatars.discourse-cdn.com/v4/letter/c/f9ae1b/32.png) [@clayton](https://community.passbolt.com/u/clayton)
#### Post date: [April 19, 2023, 11:37am UTC](https://community.passbolt.com/t/preventing-group-admins-from-accessing-system-wide-settings/7141/2 "2023-04-19T11:37:03Z")

</div>

hey @schester welcome to the forum!

You are correct that right now there are only 2 levels for users. The admins and the regular users.

Generally the approach to this problem would be an admin creates the groups and assigns a regular user as the group manager, the group manager would then have the ability to add and remove users from the group but not have access to the other admin settings.

Alternatively if you have AD/LDAP set up this can be used for group management in the Pro version

---

<div class="post-metadata">

### Author: ![garrett](https://yyz1.discourse-cdn.com/flex031/user_avatar/community.passbolt.com/garrett/32/545_2.png) [@garrett](https://community.passbolt.com/u/garrett)
#### Post date: [April 19, 2023, 1:20pm UTC](https://community.passbolt.com/t/preventing-group-admins-from-accessing-system-wide-settings/7141/3 "2023-04-19T13:20:29Z")

</div>

> [@Modifying the front end](https://community.passbolt.com/t/modifying-the-front-end/7018/5):
>
> @cedric This looks really good. I can see use of repos positioned in the future as more for additions of new feature. Given the options related to not seeing other users, it could provide more of what I would call a “passbolt for professionals” where it’s a 1 to many use case and the many don’t know each other. One point of feedback: For the options where there is the use of password/passwords it’s not clear what difference plural makes from singular. Meaning, I think singular can always be use…

@schester Something related to this was posted here, regarding the idea of a new feature to handle app configuration authorizations.
