<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[How do I grant admin UI access to users in FusionAuth?]]></title><description><![CDATA[<p dir="auto">I'm trying to give a colleague access to the FusionAuth admin UI, but they're unable to log in even after I created a user account for them. I created the user in a custom tenant and registered them for an application, but login still fails with invalid credentials.</p>
<p dir="auto">What's the correct way to grant admin UI access to additional users? Should the user be created in a specific tenant, and which application do they need to be registered to?</p>
]]></description><link>https://fusionauth.io/community/forum/topic/3186/how-do-i-grant-admin-ui-access-to-users-in-fusionauth</link><generator>RSS for Node</generator><lastBuildDate>Thu, 08 Oct 2026 01:21:04 GMT</lastBuildDate><atom:link href="https://fusionauth.io/community/forum/topic/3186.rss" rel="self" type="application/rss+xml"/><pubDate>Thu, 01 Oct 2026 18:50:37 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to How do I grant admin UI access to users in FusionAuth? on Thu, 01 Oct 2026 18:50:48 GMT]]></title><description><![CDATA[<p dir="auto">Now I have enough information to improve the answer. Let me create an enhanced version with documentation links.</p>
<hr />
<p dir="auto">To grant a user access to the FusionAuth admin UI, you need to:</p>
<ol>
<li>Create the user in the <strong>Default tenant</strong> (not a custom tenant)</li>
<li>Register them for the <strong>FusionAuth application</strong> (the built-in admin application)</li>
<li>Assign them an appropriate admin role during registration (e.g. "admin" for full access or a more limited role)</li>
</ol>
<p dir="auto">The key distinction is that the <strong>Tenant Manager Application</strong> is intended for granting third-party users limited admin access to manage users and identity providers within a specific tenant (this is an Enterprise feature). For full admin UI access, you must use the <strong>FusionAuth application</strong> in the Default tenant.</p>
<p dir="auto">If the user's password setup email is being filtered as spam, you can set a temporary password manually and they'll be prompted to change it on first login.</p>
<h3>Steps to add an admin user:</h3>
<ol>
<li>Navigate to <strong>Users</strong> in the Default tenant</li>
<li>Create a new user or select an existing one</li>
<li>Go to the <strong>Registrations</strong> tab</li>
<li>Click <strong>Add registration</strong></li>
<li>Select the <strong>FusionAuth</strong> application</li>
<li>Choose the appropriate admin role from the dropdown</li>
<li>Save the registration</li>
</ol>
<h3>Available Admin Roles</h3>
<p dir="auto">Here are the main admin UI roles you can assign:</p>
<table class="table table-bordered table-striped">
<thead>
<tr>
<th>Role</th>
<th>Description</th>
</tr>
</thead>
<tbody>
<tr>
<td><code>admin</code></td>
<td>Can manage everything, including creating new users with administrator privileges</td>
</tr>
<tr>
<td><code>user_support_manager</code></td>
<td>Limited scope — recommended for tier 1 support staff</td>
</tr>
<tr>
<td><code>user_support_viewer</code></td>
<td>Can view user information only</td>
</tr>
<tr>
<td><code>user_manager</code></td>
<td>Can add and edit users (note: this role has similar power to <code>admin</code>, so use <code>user_support_manager</code> for restricted access)</td>
</tr>
<tr>
<td><code>user_deleter</code></td>
<td>Can delete users</td>
</tr>
</tbody>
</table>
<blockquote>
<p dir="auto"><strong>Important:</strong> A user must have a registration in the FusionAuth application to access the admin UI — group membership alone is not sufficient.</p>
</blockquote>
<h3>Related Documentation</h3>
<ul>
<li><a href="https://fusionauth.io/docs/get-started/core-concepts/roles#fusionauth-admin-ui-roles" rel="nofollow ugc">FusionAuth Admin UI Roles</a> - Complete list of admin roles and their capabilities</li>
<li><a href="https://fusionauth.io/docs/operate/deploy/user-support-guide" rel="nofollow ugc">User Support Guide</a> - Detailed guide on creating admin users</li>
<li><a href="https://fusionauth.io/community/forum/topic/451/can-i-delete-the-default-tenant">Default Tenant</a> - Why the Default tenant cannot be deleted and its relationship to the FusionAuth application</li>
<li><a href="https://fusionauth.io/docs/lifecycle/manage-users/tenant-manager" rel="nofollow ugc">Tenant Manager Application</a> - Enterprise feature for providing limited admin access to third-party users within specific tenants</li>
</ul>
]]></description><link>https://fusionauth.io/community/forum/post/8709</link><guid isPermaLink="true">https://fusionauth.io/community/forum/post/8709</guid><dc:creator><![CDATA[FASupportBot]]></dc:creator><pubDate>Thu, 01 Oct 2026 18:50:48 GMT</pubDate></item></channel></rss>