Security levels

About security levels

A security level is a named, reusable set of rules that defines the access users have when logged in to Datto RMM. Each security level defines user access for these three categories: 

  • Device visibility: Which sites, groups, and devices a user can see.

  • Permissions: What areas of Datto RMM a user can view or manage.

  • Remote control tools: Which remote tools a user can use when connecting to devices.

When a user logs in to the web interface or the Agent Browser, Datto RMM grants that user exactly the access defined by their default security level.

A user can be assigned several security levels and switch between them, but only one is active at a time. Assigning a user a second security level does not combine the permissions from both security levels. Only the active security level determines their access. Users can switch security levels in the web interface and the Agent Browser.

IMPORTANT  You must be logged in with the Administrator security level to be able to add, edit, copy, or delete a security level. For more information, refer to Users.

NOTE  If integrated with KaseyaOne, and access groups are enabled, the following warning will appear at the top of the page: 

Refer to Automatically assign access to Datto RMM based on KaseyaOne groups.

Administrator security level

The Administrator security level is a static security level that grants full and unlimited access to all Datto RMM functionality and the ability to see and connect to all devices in the Datto RMM account.

By default, the Administrator security level is assigned to the initial user who registers a Datto RMM account, and it is the only security level available to assign to new users until other security levels are created. The Administrator security level cannot be modified or edited in any way.

Creating a security level

On the Security Levels page, click Create Security Level and specify the security level details.

Viewing and managing security levels

Best practices (security level templates)

Navigate to the Security Levels page by following the navigation path described in Security and navigation. Click Best Practices and then click Create next to one of the security level templates.

These templates serve as guides with recommended settings for common use cases; however, you can change any of the settings before saving the security level. Refer to Creating a security level.

Potential configurations for co-managed environments

Some of the users you invite to your Datto RMM account may require security level configurations that accommodate specific employee or customer roles and tasks. These configurations accomplish a combination of fully granting, somewhat restricting, or completely denying access to relevant features and functions in Datto RMM. In any co-managed scenario, you can restrict or grant global access to each feature of Datto RMM (for example, permission to view dashboards). This granularity is useful, as you may want to restrict certain users to accessing only what is relevant to their site and not accessing any global settings. Dashboards, for example, will reflect data of only the devices the logged-in user has access to. For any user that has access only to devices and not to full sites, dashboards are completely hidden, even with View permission for Global dashboards enabled.

IMPORTANT  The following configurations are recommended best practices. When you create any customized security level, Datto RMM highly recommends adding your own user account in the Membership section, switching your user account to that security level, and testing out the configuration before officially assigning other users to the security level. Refer to Switching security levels.