Skip to main content
Version: 2.2.0

Realm Roles

IAMS require the following realm roles to be created:

  • realm-tenant-admin – role that can create tenant
  • tenant-admin – role that can administer role, group, resource, and resource permission in a tenant.
  • system-admin – role that can manage user and tenant in the realm. This role is a composite role that contain the realm-tenant-admin role.

Create realm-tenant-admin Role

  1. Login to the Web Admin Console and navigate to the realm.

  2. Click on Realm roles on the side menu:

Realm Roles

  1. Click on Create role button

Realm Roles

  1. Enter the following for the role:
  • Role name: realm-tenant-admin
  1. Click on Save button to create

Realm Roles

Create system-admin Role

  1. Login to the Web Admin Console and navigate to the realm.

  2. Click on Realm roles on the side menu.

  3. Click on Create role button

  4. Enter the following for the role:

  • Role name: system-admin
  1. Click on Save button to create the role.

  2. Click on the Action dropdown menu on the right hand side of the screen and select Add associated roles submenu.

Add Associated Roles

  1. Check realm-management realm-admin from the list:

Realm List

  1. Click on Assign button to assign selected roles to system-admin role:

Assign to System admin

  1. Click on Assign Role button

Assign to System admin

  1. Select Filter by realm roles from the filter

Filter by realm roles

  1. Check realm-tenant-admin from the list

Filter by realm roles

  1. Click on Assign button to complete the configuration.

Filter by realm roles

Create tenant-admin Role

  1. Login to the Web Admin Console and navigate to the realm.

  2. Click on Realm roles on the side menu.

  3. Click on Create role button

  4. Enter the following for the role:

Role name: tenant-admin

  1. Click on Save button to create the role.

  2. Click on the Action dropdown menu on the right hand side of the screen and select Add associated roles submenu.

  3. Check realm-management realm-admin from the list.

  4. Click on Assign button to assign selected roles to tenant-admin role.