FusionAuth
    • Home
    • Categories
    • Recent
    • Popular
    • Pricing
    • Contact us
    • Docs
    • Login

    How do I grant admin UI access to users in FusionAuth?

    Scheduled Pinned Locked Moved Solved
    Frequently Asked Questions (FAQ)
    admin-ui users registration roles authentication
    1
    2
    1
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • F
      FASupportBot
      last edited by

      I'm trying to give a colleague access to the FusionAuth admin UI, but they're unable to log in even after I created a user account for them. I created the user in a custom tenant and registered them for an application, but login still fails with invalid credentials.

      What's the correct way to grant admin UI access to additional users? Should the user be created in a specific tenant, and which application do they need to be registered to?

      If you are looking for professional support and not just bot-provided support, please check out https://fusionauth.io/pricing and pick a plan that fits your needs.

      1 Reply Last reply Reply Quote 0
      • F
        FASupportBot
        last edited by

        Now I have enough information to improve the answer. Let me create an enhanced version with documentation links.


        To grant a user access to the FusionAuth admin UI, you need to:

        1. Create the user in the Default tenant (not a custom tenant)
        2. Register them for the FusionAuth application (the built-in admin application)
        3. Assign them an appropriate admin role during registration (e.g. "admin" for full access or a more limited role)

        The key distinction is that the Tenant Manager Application is intended for granting third-party users limited admin access to manage users and identity providers within a specific tenant (this is an Enterprise feature). For full admin UI access, you must use the FusionAuth application in the Default tenant.

        If the user's password setup email is being filtered as spam, you can set a temporary password manually and they'll be prompted to change it on first login.

        Steps to add an admin user:

        1. Navigate to Users in the Default tenant
        2. Create a new user or select an existing one
        3. Go to the Registrations tab
        4. Click Add registration
        5. Select the FusionAuth application
        6. Choose the appropriate admin role from the dropdown
        7. Save the registration

        Available Admin Roles

        Here are the main admin UI roles you can assign:

        Role Description
        admin Can manage everything, including creating new users with administrator privileges
        user_support_manager Limited scope — recommended for tier 1 support staff
        user_support_viewer Can view user information only
        user_manager Can add and edit users (note: this role has similar power to admin, so use user_support_manager for restricted access)
        user_deleter Can delete users

        Important: A user must have a registration in the FusionAuth application to access the admin UI — group membership alone is not sufficient.

        Related Documentation

        • FusionAuth Admin UI Roles - Complete list of admin roles and their capabilities
        • User Support Guide - Detailed guide on creating admin users
        • Default Tenant - Why the Default tenant cannot be deleted and its relationship to the FusionAuth application
        • Tenant Manager Application - Enterprise feature for providing limited admin access to third-party users within specific tenants

        If you are looking for professional support and not just bot-provided support, please check out https://fusionauth.io/pricing and pick a plan that fits your needs.

        1 Reply Last reply Reply Quote 0
        • danD dan has marked this topic as solved
        • danD dan moved this topic from Staged
        • First post
          Last post