Community discussions

MikroTik App
 
ytuxedo002
Frequent Visitor
Frequent Visitor
Topic Author
Posts: 62
Joined: Fri Apr 13, 2012 11:36 pm

Super User

Fri Jun 27, 2014 12:51 am

Hey guys and gals, i got a quick one.

I basically need two admin accounts but I need that the second one to have admin access but not be able to delete/disable/change pw on the first user.

What i need is access for our engineers to manage the MT's but also let the local admin have access as well but we don't want him changing our access.

Is this possible?

Regards
 
User avatar
rextended
Forum Guru
Forum Guru
Posts: 12557
Joined: Tue Feb 25, 2014 12:49 pm
Location: Italy
Contact:

Re: Super User

Fri Jun 27, 2014 1:13 am

you can create another group for admin users without be super "policy" users:
/user group
add name=near-full policy="local,telnet,ssh,ftp,reboot,read,write,test,winbox,web,sniff,api,sensitive,password,!policy"
If the user NOT have "policy" right can not modify password or delete user account
Last edited by rextended on Fri Jun 27, 2014 1:23 am, edited 2 times in total.
 
ytuxedo002
Frequent Visitor
Frequent Visitor
Topic Author
Posts: 62
Joined: Fri Apr 13, 2012 11:36 pm

Re: Super User

Fri Jun 27, 2014 1:21 am

you can create another group for admin users without be super users:
/user group
add name=near-full policy="local,telnet,ssh,ftp,reboot,read,write,test,winbox,web,sniff,api,sensitive,password,!policy"
Beautiful. I will implement this and let you know how it works out. But I can tell that this will work just fine. Thank you sir.
 
User avatar
rextended
Forum Guru
Forum Guru
Posts: 12557
Joined: Tue Feb 25, 2014 12:49 pm
Location: Italy
Contact:

Re: Super User

Fri Jun 27, 2014 1:24 am

you can create another group for admin users without be super users:
/user group
add name=near-full policy="local,telnet,ssh,ftp,reboot,read,write,test,winbox,web,sniff,api,sensitive,password,!policy"
Beautiful. I will implement this and let you know how it works out. But I can tell that this will work just fine. Thank you sir.
BUT...

there is more than one way for right excalation, if the admin know the way...

Who is online

Users browsing this forum: Elvis1991, eworm, own3r1138 and 30 guests