# Roles Matrix **Mobile Device Manager Plus** lets administrators designate roles to users. Apart from a set of predefined roles, MDM supports customization of roles as per the needs of your organization. For each of these user-defined roles, the permission to access specific sections of MDM can be configured as Full control, Write, Read or No access, as given in the table below. > The below actions can be performed as per the permissions assigned for the created role. > For example **Enroll Device** action can only be performed by an **Admin** who have **Full control permission**. Visit our [Permission Guide](https://www.manageengine.com/mobile-device-management/help/configuring_mobile_device_manager/user_admin_roles_permissions.html#Permissions) for more details. ## Module specific access ### Enrollment | ACTION | DESCRIPTION | FULL CONTROL | WRITE | READ | |---|---|---|---|---| | **ENROLL DEVICE (Admin)** | Admin Enrollment methods (except EMM) like **ZTE, ABM, Knox** | ![](https://www.manageengine.com/mobile-device-management/help/images/success.png) | ![](https://www.manageengine.com/mobile-device-management/help/images/failured.gif) | ![](https://www.manageengine.com/mobile-device-management/help/images/failured.gif) | | **ENROLL DEVICE (Invite)** | Invite Enrollment methods like Self Enrollment | ![](https://www.manageengine.com/mobile-device-management/help/images/success.png) | ![](https://www.manageengine.com/mobile-device-management/help/images/success.png) | ![](https://www.manageengine.com/mobile-device-management/help/images/failured.gif) | | **ADD/MODIFY AD** | Upload and renew Directory Services | ![](https://www.manageengine.com/mobile-device-management/help/images/success.png) | ![](https://www.manageengine.com/mobile-device-management/help/images/failured.gif) | ![](https://www.manageengine.com/mobile-device-management/help/images/failured.gif) | | **APN'S CONFIGURATION** | Add or remove Apple Push Notification Ceritificates | ![](https://www.manageengine.com/mobile-device-management/help/images/success.png) | ![](https://www.manageengine.com/mobile-device-management/help/images/failured.gif) | ![](https://www.manageengine.com/mobile-device-management/help/images/failured.gif) | | **CONFIGURING ABM TOKEN** | Access the Public key and upload the server token | ![](https://www.manageengine.com/mobile-device-management/help/images/success.png) | ![](https://www.manageengine.com/mobile-device-management/help/images/failured.gif) | ![](https://www.manageengine.com/mobile-device-management/help/images/failured.gif) | | **CONFIGURING ENROLLMENT SETTINGS** | Configure the MDM Server authentication protocol,Device policy | ![](https://www.manageengine.com/mobile-device-management/help/images/success.png) | ![](https://www.manageengine.com/mobile-device-management/help/images/failured.gif) | ![](https://www.manageengine.com/mobile-device-management/help/images/failured.gif) | | **KNOX ENROLLMENT** | Confugure the Knox Profile in MDM Server | ![](https://www.manageengine.com/mobile-device-management/help/images/success.png) | ![](https://www.manageengine.com/mobile-device-management/help/images/failured.gif) | ![](https://www.manageengine.com/mobile-device-management/help/images/failured.gif) | | **ZTE ENROLLMENT** | Access the ZTE configuration | ![](https://www.manageengine.com/mobile-device-management/help/images/success.png) | ![](https://www.manageengine.com/mobile-device-management/help/images/failured.gif) | ![](https://www.manageengine.com/mobile-device-management/help/images/failured.gif) | | **ENROLL LAPTOP/SURFACE PRO** | Downloading enrollment tool,assigning users to devices | ![](https://www.manageengine.com/mobile-device-management/help/images/success.png) | ![](https://www.manageengine.com/mobile-device-management/help/images/failured.gif) | ![](https://www.manageengine.com/mobile-device-management/help/images/failured.gif) | | **AZURE ENROLLMENT** | Setting up Azure Portal and adding devices | ![](https://www.manageengine.com/mobile-device-management/help/images/success.png) | ![](https://www.manageengine.com/mobile-device-management/help/images/failured.gif) | ![](https://www.manageengine.com/mobile-device-management/help/images/failured.gif) | | **CHROMEBOOK ENROLLMENT** | Enrolling Chrome devices | ![](https://www.manageengine.com/mobile-device-management/help/images/success.png) | ![](https://www.manageengine.com/mobile-device-management/help/images/success.png) | ![](https://www.manageengine.com/mobile-device-management/help/images/failured.gif) | | **CONFIGURE AGENT SETTNGS** | Configure the Andriod/iOS MEMDM App Settings | ![](https://www.manageengine.com/mobile-device-management/help/images/success.png) | ![](https://www.manageengine.com/mobile-device-management/help/images/failured.gif) | ![](https://www.manageengine.com/mobile-device-management/help/images/failured.gif) | | **DEVICE ACTIONS** | Re-assign User,Enroll Additional Device,Deprovision | ![](https://www.manageengine.com/mobile-device-management/help/images/success.png) | ![](https://www.manageengine.com/mobile-device-management/help/images/success.png) | ![](https://www.manageengine.com/mobile-device-management/help/images/failured.gif) | ### Profile Management | ACTION | DESCRIPTION | FULL CONTROL | WRITE | READ | |---|---|---|---|---| | **CREATE PROFILE** | Create profiles for iOS,Android,Windows,Chrome,macOS,tvOS devices | ![](https://www.manageengine.com/mobile-device-management/help/images/success.png) | ![](https://www.manageengine.com/mobile-device-management/help/images/failured.gif) | ![](https://www.manageengine.com/mobile-device-management/help/images/failured.gif) | | **MODIFY/UPDATE PROFILE** | Update existing profiles | ![](https://www.manageengine.com/mobile-device-management/help/images/success.png) | ![](https://www.manageengine.com/mobile-device-management/help/images/failured.gif) | ![](https://www.manageengine.com/mobile-device-management/help/images/failured.gif) | | **MOVE TO TRASH/ DLT TRASH** | Remove profiles | ![](https://www.manageengine.com/mobile-device-management/help/images/success.png) | ![](https://www.manageengine.com/mobile-device-management/help/images/failured.gif) | ![](https://www.manageengine.com/mobile-device-management/help/images/failured.gif) | | **VIEW TRASH** | View removed profiles, restore profiles, delete profile permanently | ![](https://www.manageengine.com/mobile-device-management/help/images/success.png) | ![](https://www.manageengine.com/mobile-device-management/help/images/failured.gif) | ![](https://www.manageengine.com/mobile-device-management/help/images/failured.gif) | | **DISTRIBUTE PROFILE** | Distribute published profiles to groups/devices | ![](https://www.manageengine.com/mobile-device-management/help/images/success.png) | ![](https://www.manageengine.com/mobile-device-management/help/images/success.png) | ![](https://www.manageengine.com/mobile-device-management/help/images/failured.gif) | | **REMOVE ASSOCIATED PROFILE** | Disassociate redundant profiles from groups/devices | ![](https://www.manageengine.com/mobile-device-management/help/images/success.png) | ![](https://www.manageengine.com/mobile-device-management/help/images/success.png) | ![](https://www.manageengine.com/mobile-device-management/help/images/failured.gif) | | **VIEW PROFILE DETAILS** | View the different policies and restrictions implemented by a profile | ![](https://www.manageengine.com/mobile-device-management/help/images/success.png) | ![](https://www.manageengine.com/mobile-device-management/help/images/success.png) | ![](https://www.manageengine.com/mobile-device-management/help/images/success.png) | *Note: Additional modules (App Management, Deprovision, Content Management, Group Management, Inventory Management, OS Update Management, Remote Control, Announcements, Reports, and Query Reports) follow the same permission structure of Full Control, Write, and Read as defined in the original matrix.*