Skip to main content

August 25, 2026

Managing Admin Roles

Omnissa App Volumes has built-in roles with assigned privileges for managing App Volumes Manager. In addition to the built-in roles, you can create custom roles and assign necessary privileges to this role.

You can assign built-in roles or custom roles to a directory service group. All users within the group inherit the privileges defined for the role. When Entra ID is the registered domain, ensure that the user belongs to the group (in the Azure portal) which is assigned the built-in or custom role with responsibilities specific to that role. For example: Consider AzureTestAdmins as a group in Microsoft Azure which is assigned the Administrators role in App Volumes Manager. A user, who is required to have all the responsibilities associated with the Administrators role, must belong to the AzureTestAdmins group.

To change the directory service group, you can edit the assignment. You can also remove the role from the assigned directory service group. However, you can only edit or remove a custom role.

Built-in Roles

RolesResponsibilities
AdministratorsYou can perform all operations including adding and setting permissions for other administrators.
Applications AdministratorsYou can perform the following operations:
  • In the Inventory tab - create and manage applications, assign and unassign entities from applications, view assignments, set and unset markers, view programs, create and manage packages, and view application attachments.
  • In the Directory tab - view the online entities and perform view and sync on all the entity types (User, Group, Computer, and OU.
  • In the Infrastructure tab - view and rescan machines, storages, and storage groups and view instances.
  • In the Activity tab - view pending actions, activity log, system messages, server log, and jobs and view and create troubleshooting archives.
  • In the Configuration tab, view settings.

    You have no access to any other operation in this tab.

Note: You have no access to Writable Volumes.
Applications OwnersYou can access applications and perform related operations only on those applications which are owned by the entity User either as the owner of an application or belonging to a Group that owns the application.

This role allows you to define application-based access policy where the user can view and edit only those applications for which the User is assigned as the owner of the applications. Unlike the other built-in roles, the privileges of this role can be edited. However, the name and description of the role cannot be changed. For more information about this role, see the section Applications Owners on this page.
Inventory AdministratorsYou can perform the following operations:
  • Application-based tasks such as create, import, rescan, update, and so on.
  • Writable Volumes-based tasks such as create, import, update, rescan, and so on.
  • View resources in the Directory or Infrastructure tabs.
You have no access to resources in the Configuration tab.
Administrators (Read only)You can view resources but cannot make any modifications or perform other tasks. For more information, see the Administrators (Read only) section on this page.
Security AdministratorsYou can perform the following operations:
Writables AdministratorsYou can perform the following:
  • Create, import, update, back up and similar operations on Writable Volumes.
  • View resources in these tabs: Directory, Infrastructure, Storage Groups, and so on.
You have no access to resources in the Configuration tab.

Administrators (Read only)

This administrator role can only view the resources and configuration information but cannot perform any other tasks. Specifically, a read-only administrator cannot perform the following functions:

  1. Make configuration changes to the App Volumes Manager.
  2. Create or import Application Packages.
  3. Make storage configuration changes.
  4. Add or remove directory service domains.
  5. Add or remove Machine Managers.
  6. Create, import, or update writable volumes.

Only an existing administrator, who has complete access to App Volumes Manager functionality, can add the Administrator (Read only) role.

As an administrator, you can add a read-only account to a group of users that belong to a particular domain. For example, if you have created a domain xyz.com, then you can create a read-only account belonging to the domain xyz.com.

Note: You cannot create a read-only account for a single user.

Applications Owners

The following operations can be performed by the members of the Group which is assigned the Applications Owners role:

Important: A User can perform these operations only on those applications that are either directly owned by the User or the Group where the User is a member.

As a result, ensure that when creating or editing the Owner field of an application, you select the User who belongs to the Group, which is assigned this role or you select the Group which is assigned this role. To create or edit an application, see Create an App Volumes Application and Edit an App Volumes Application respectively.

  • Create applications.
  • View, Edit, or Delete applications.
  • Assign or unassign entities from applications.
  • View application assignments and programs.
  • Set or unset markers on application packages.
  • Create and manage application packages.

Note: If you determine to not provide any of these privileges, ensure that you are aware of how this impacts the User when using the App Volumes Manager admin UI. For example: If you do not provide the set/unset marker privilege, the Set CURRENT and Unset CURRENT operations are not permitted for the User in the App Volumes Manager admin UI.

The User can be granted permission through other roles. If you assign another role to a Group where the User belongs, the User also gets the capabilities of that role irrespective of the application. For example: If a Group is assigned the Inventory Administrators and Applications Owners roles, then the members of this group can view all the applications and not just those applications owned by them.

Custom Roles

You can create custom roles with specific privileges and assign them to groups. Whenever privileges are changed for the custom roles, they are dynamically updated and the members of the group receive the updated privileges immediately.

You can assign multiple roles to a group. In such a case, the group receives the union of the privileges of the different roles assigned to it.

Note: When a new role is assigned to a group, the users of the group must log out and log in again to the system before they can get the privileges offered by the role.

  • View-only access to other resources such as Directory or Infrastructure.
  • No access to Configuration or Writable Volumes.

Was this page helpful?

Provide feedback for this topic

Was this topic helpful?

Please do not include any personal or confidential information.

Generating link…