Security levels

About security levels

Security levels specify and limit the access users have when logged in to the Datto RMM web interface, the Agent Browser, or a Web Remote session or chat. Users can have more than one security level and change them as needed. Security levels can be added, edited, copied, and deleted. Users can switch security levels in the web interface and the Agent Browser.

IMPORTANT  You must have the Administrator security level to be able to add, edit, copy, or delete a security level. For more information, refer to Users.

NOTE  If integrated with KaseyaOne, and access groups are enabled, the following warning will appear at the top of the page: 

Refer to Automatically assign access to Datto RMM based on KaseyaOne groups.

Administrator security level

By default, the Administrator security level is assigned to the user who registers a Datto RMM account, and it is the only security level available to assign to new users until other security levels are created. The Administrator security level cannot be modified or edited in any way. Users who have this security level assigned have full and unlimited access to all Datto RMM functionality and can see and connect to all devices in the Datto RMM account.

Creating a security level

On the Security Levels page, click Create Security Level and specify the security level details.

Viewing and managing security levels

Best practices (security level templates)

Navigate to the Security Levels page by following the navigation path described in Security and navigation. Click Best Practices and then click Create next to one of the security level templates.

These templates serve as guides with recommended settings for common use cases; however, you can change any of the settings before saving the security level. Refer to Creating a security level.

Potential configurations for co-managed environments

Some of the users you invite to your Datto RMM account may require security level configurations that accommodate specific employee or customer roles and tasks. These configurations accomplish a combination of fully granting, somewhat restricting, or completely denying access to relevant features and functions in Datto RMM. In any co-managed scenario, you can restrict or grant global access to each feature of Datto RMM (for example, permission to view dashboards). This granularity is useful, as you may want to restrict certain users to accessing only what is relevant to their site and not accessing any global settings. Dashboards, for example, will reflect data of only the devices the logged-in user has access to. For any user that has access only to devices and not to full sites, dashboards are completely hidden, even with View permission for Global dashboards enabled.

IMPORTANT  The following configurations are recommended best practices. When you create any customized security level, Datto RMM highly recommends adding your own user account in the Membership section, switching your user account to that security level, and testing out the configuration before officially assigning other users to the security level. Refer to Switching security levels.