Authentication permissions by role and by action

Authentication settings cover two-factor authentication (2FA, also called multi-factor authentication), Login.gov, and Security Assertion Markup Language (SAML) single sign-on with an identity provider (IdP). A user's role determines who can require, reset, and configure these settings. This article lists the authentication permissions for each role and for each action.

Roles referenced on this page: Users with the Admin, Group Admin, Portfolio Manager, Operations, Internal Business User, User, or View Only role.

What can my role do?

Use this section to find everything a specific role can and can't do with authentication settings. For a breakdown by action instead, see By action below.

What can an Admin do with authentication settings?
  • Can require users to implement 2FA.
  • Can implement 2FA for their own account.
  • Can set up Login.gov.
  • Can reset 2FA so a user can implement it again.
  • Can manage SAML, including disabling SAML and setting up an integration with an identity provider.
What can a Group Admin do with authentication settings?
  • Can implement 2FA for their own account.
  • Cannot require users to implement 2FA.
  • Cannot set up Login.gov.
  • Cannot reset 2FA for other users.
  • Cannot manage SAML.
What can a Portfolio Manager do with authentication settings?
  • Can implement 2FA for their own account.
  • Cannot require users to implement 2FA.
  • Cannot set up Login.gov.
  • Cannot reset 2FA for other users.
  • Cannot manage SAML.
What can an Operations user do with authentication settings?
  • Can implement 2FA for their own account.
  • Cannot require users to implement 2FA.
  • Cannot set up Login.gov.
  • Cannot reset 2FA for other users.
  • Cannot manage SAML.
What can an Internal Business User do with authentication settings?
  • Can implement 2FA for their own account.
  • Cannot require users to implement 2FA.
  • Cannot set up Login.gov.
  • Cannot reset 2FA for other users.
  • Cannot manage SAML.
What can a User do with authentication settings?
  • Can implement 2FA for their own account.
  • Cannot require users to implement 2FA.
  • Cannot set up Login.gov.
  • Cannot reset 2FA for other users.
  • Cannot manage SAML.
What can a View Only user do with authentication settings?
  • Can implement 2FA for their own account.
  • Cannot require users to implement 2FA.
  • Cannot set up Login.gov.
  • Cannot reset 2FA for other users.
  • Cannot manage SAML.

By action

Permissions key

✅ = Is permitted.

❌ = Not permitted.

➖ = Not applicable and not permitted.

Enforce 2FA

Require users to implement 2FA.

✅ Only Admins can do this.

❌ No other role can require 2FA.
 

Implement 2FA

Implement 2FA for your own account.

✅ All roles can do this.
 

Login.gov

Set up Login.gov.

✅ Only Admins can do this.

❌ No other role can set up Login.gov.
 

Reset 2FA

Reset 2FA so a user can implement it again.

✅ Only Admins can do this.

❌ No other role can reset 2FA.
 

SAML

Manage SAML: disable SAML, or set up SAML and integrate with an identity provider.

✅ Only Admins can do this.

❌ No other role can manage SAML.
 

Publish Date or Recent Edits
  • December 17, 2024: Disable SAML; Login.gov.
  • November 25, 2024: Separated from User Permissions and added VRM/TMH roles.
Was this article helpful?
0 out of 0 found this helpful

Comments

0 comments

Please sign in to leave a comment.