Category Filter

Last updated: August 13, 2026

Roles Matrix

The Roles Matrix in Mobile Device Manager Plus is a comprehensive permission reference that maps every MDM action to the required access level — Full Control, Write, or Read. Administrators can use this matrix to configure user-defined roles with precise, module-level access control across areas such as Enrollment, Profile Management, and App Management, ensuring each role is granted only the permissions necessary for its responsibilities within the MDM environment.

Mobile Device Manager Plus lets administrators designate roles to users. Apart from a set of predefined roles, MDM supports customization of roles as per the needs of your organization. For each of these user-defined roles, the permission to access specific sections of MDM can be configured as Full control, Write, Read or No access, as given in the table below.

The below actions can be performed as per the permissions assigned for the created role.
For example Enroll Device action can only be performed by an Admin who have Full control permission. Visit our Permission Guide for more details.

Module specific access

Enrollment
ACTIONDESCRIPTIONPERMISSIONS
FULL CONTROLWRITEREAD
ENROLL DEVICE (Admin)Admin Enrollment methods (except EMM) like ZTE, ABM, KnoxSuccessFailuredFailured
ENROLL DEVICE (Invite)Invite Enrollment methods like Self EnrollmentSuccessSuccessFailured
ADD/MODIFY ADUpload and renew Directory ServicesSuccessFailuredFailured
APN'S CONFIGURATIONAdd or remove Apple Push Notification CeritificatesSuccessFailuredFailured
CONFIGURING ABM TOKENAccess the Public key and upload the server tokenSuccessFailuredFailured
CONFIGURING ENROLLMENT SETTINGSConfigure the MDM Server authentication protocol,Device policySuccessFailuredFailured
KNOX ENROLLMENTConfugure the Knox Profile in MDM ServerSuccessFailuredFailured
ZTE ENROLLMENTAccess the ZTE configurationSuccessFailuredFailured
ENROLL LAPTOP/SURFACE PRODownloading enrollment tool,assigning users to devicesSuccessFailuredFailured
AZURE ENROLLMENTSetting up Azure Portal and adding devicesSuccessFailuredFailured
CHROMEBOOK ENROLLMENTEnrolling Chrome devicesSuccessSuccessFailured
CONFIGURE AGENT SETTNGSConfigure the Andriod/iOS MEMDM App SettingsSuccessFailuredFailured
DEVICE ACTIONSRe-assign User,Enroll Additional Device,DeprovisionSuccessSuccessFailured
Profile Management
ACTIONDESCRIPTIONPERMISSIONS
FULL CONTROLWRITEREAD
CREATE PROFILECreate profiles for iOS,Android,Windows,Chrome,macOS,tvOS devicesSuccessFailuredFailured
MODIFY/UPDATE PROFILEUpdate existing profilesSuccessFailuredFailured
MOVE TO TRASH/ DLT TRASHRemove profilesSuccessFailuredFailured
VIEW TRASHView removed profiles, restore profiles, delete profile permanentlySuccessFailuredFailured
DISTRIBUTE PROFILEDistribute published profiles to groups/devicesSuccessSuccessFailured
REMOVE ASSOCIATED PROFILEDisassociate redundant profiles from groups/devicesSuccessSuccessFailured
VIEW PROFILE DETAILSView the different policies and restrictions implemented by a profileSuccessSuccessSuccess
App Management
ACTIONDESCRIPTIONPERMISSIONS
FULL CONTROLWRITEREAD
ADD/MODIFY APPSAdd Enterprise and Store apps to App repositorySuccessFailuredFailured
DELETE APPSMoving apps from App Repository to TrashSuccessFailuredFailured
DISTRIBUTE APPSDistributing Apps from app repository to groups/devicesSuccessSuccessFailured
CONFIGURE ABM/VPPUpload location token for adding apps from ABM portalSuccessFailuredFailured
SYNC ABM/ VPP APPSSyncing apps added from ABM portalSuccessFailuredFailured
UPDATE APPSUpdating exisitng apps to latest app versionsSuccessFailuredFailured
AUTOMATE APP UPDATESPermission to setup automate app update policySuccessSuccessFailured
APPROVE SPECIFIC APP VERSIONApproving a specific app version among multiple versions presentSuccessSuccessFailured
DELETE SPECIFIC APP VERSIONDeleting an outdated app version from the serverSuccessFailuredFailured
ADD/ MODIFY APP PERMISSIONMake changes to existing app permissions provided by the app developerSuccessFailuredFailured
ADD/ MODIFY APP CONFIGURATIONMake changes to existing app configuration provided by the app developerSuccessFailuredFailured
ADD ENTERPRISE APPSAdding In-house/ Enterprise apps specificallySuccessFailuredFailured
REMOVE MANAGED APPSRemove unwanted Apps from Server to trashSuccessFailuredFailured
Deprovision
ACTIONDESCRIPTIONPERMISSIONS
FULL CONTROLWRITEREAD
Factory reset device (Complete wipe) Wipe all the data present in the device.SuccessFailuredFailured
Revoke MDM(Corporate wipe)Wipe only the corporate data present in the device.SuccessSuccessFailured
Content Management
ACTIONDESCRIPTIONPERMISSIONS
FULL CONTROLWRITEREAD
ADD/ UPDATE/ DELETE DOCSAdd Documents to MDM ServerSuccessFailuredFailured
DISTRIBUTE DOCSDistribute docs via server to groups and devicesSuccessSuccessFailured
CREATE POLICIESCreate policies to view or share documentsSuccessFailuredFailured
VIEW POLICIESView existing policies applied to devicesSuccessSuccessSuccess
Group Management
ACTIONDESCRIPTIONPERMISSIONS
FULL CONTROLWRITEREAD
VIEW GROUPS & DETAILSSight group members, policies, app associationsSuccessSuccessSuccess
CREATE GROUPSCreate User group,Device group, AD User groupSuccessSuccessFailured
MODIFY GROUP DETAILSModify the details of a group like title, description, membersSuccessSuccessFailured
DELETE GROUPDelete groups from serverSuccessSuccessFailured
ADD MEMBERS TO A GROUPMove devices to selected groupsSuccessFailuredFailured
MOVE MEMBERS BETWEEN GROUPSMove members from one group to another if requiredSuccessFailuredFailured
REMOVE MEMBERSRemove members from groups they're no longer requiredSuccessFailuredFailured
Inventory Management
ACTIONDESCRIPTIONPERMISSIONS
FULL CONTROLWRITEREAD
EDIT DEVICE DETAILSFill in details of devices which aren't collected automaticallySuccessSuccessFailured
DEVICE ACTIONSPush Device actons like Scan, Remote View, Complete Wipe etcSuccessFailuredFailured
APP BLOCKLISTINGProvision to block apps which don't follow organizational policiesSuccessSuccessFailured
SCHEDULE DEVICE SCANSchedule Device scan frequency, timeline and tenureSuccessFailuredFailured
GEO TRACKINGConfigure Geo Tracking Settings
Note: With Geo Tracking (Full Control) enabled, admins can control the access to location tracking settings based on the specific roles.
SuccessFailuredFailured
BATTERY LEVEL TRACKINGConfigure Battery Level tracking settingSuccessFailuredFailured
CREATE/ MODIFY FENCE POLICYCreate New fence policy and configure complinace settingsSuccessSuccessFailured
CREATE /MODIFY/DELETE FENCE REPOSITORYCreate & Edit Fence RepostiorySuccessSuccessFailured
OS Update Management
ACTIONDESCRIPTIONPERMISSIONS
FULL CONTROLWRITEREAD
CREATE POLICYConfigure automate OS policy for all platformsSuccessFailuredFailured
MODIFY POLICYModify/update existing policy settingsSuccessFailuredFailured
DELETE POLICYDelete redundant/unwanted policiesSuccessFailuredFailured
ASSOCIATE/DISASSOCIATE POLICYAbiltiy to associate/ disassociate policies from groupsSuccessSuccessFailured
VIEW POLICIESPermission to read the Automate OS policies in effectSuccessSuccessSuccess
Remote Control
ACTIONDESCRIPTIONPERMISSIONS
FULL CONTROLWRITEREAD
ADD ZOHO ASSIST ACCOUNTEdit login detailsSuccessSuccessFailured
REMOTE CONTROL/ VIEWExecute Remote Control/Remote view actions on devicesSuccessSuccessFailured
VIEW REMOTE CONTROL DETAILSAccess the Remote Control settingsSuccessSuccessSuccess
Announcements
ACTIONDESCRIPTIONPERMISSIONS
FULL CONTROLWRITEREAD
CREATE ANNOUNCEMENTCreate a new announcement and publish itSuccessFailuredFailured
UPDATE ANNOUNCEMENTUpdate an exisiting announcement if requiredSuccessFailuredFailured
DELETE ANNOUNCEMENTDelete an unwanted announcement from repositorySuccessFailuredFailured
MODIFY ANNOUNCEMENTModify exisiting announcement in ActionsSuccessSuccessFailured
DISTRIBUTE ANNOUNCEMENTDistribute Announcements in ActionSuccessSuccessSuccess
REMOVE ASSOCIATED ANNOUNCEMENTRemove an announcement which is published and distributedSuccessSuccessFailured
VIEW ANNOUNCEMENT DETAILSView granular information about an announcement like Distributed devices, Acknowledged users etcSuccessSuccessSuccess
Reports
ACTIONDESCRIPTIONPERMISSIONS
FULL CONTROLWRITEREAD
VIEW PREDEFINED REPORTSAccess and view reports collected by the system by defaultSuccessSuccessSuccess
CREATE SCHEDULED REPORTSCreate scheduled reports for specific use casesSuccessSuccessFailured
VIEW SCHEDULED REPORTSView data in the scheduled reportsSuccessSuccessSuccess
CONFIGURE REPORT RETENTION PERIODRetention period is the period until which the the reports are stored in the serverSuccessSuccessFailured
Query Reports
ACTIONDESCRIPTIONPERMISSIONS
FULL CONTROLWRITEREAD
CREATE QUERY REPORTCreate Query reports for specific functionalitiesSuccessFailuredFailured
VIEW QUERY REPORTView the query reports created in the serverSuccessFailuredFailured
MODIFY QUERY REPORTUpdate or edit existing query reportsSuccessFailuredFailured

 

Frequently Asked Questions

  • What does the user roles matrix show in ManageEngine MDM? The user roles matrix in ManageEngine MDM provides a comprehensive comparison of all pre-defined and user-defined roles, showing which permissions are enabled for each role across all MDM modules.
  • Where can I find the full list of permissions available in ManageEngine MDM roles? The full list of permissions is displayed in the Roles Matrix under User Administration. It shows permissions for device management, enrollment, policy application, reporting, and administration tasks.
  • Can I use the roles matrix to plan custom role creation in ManageEngine MDM? Yes. The roles matrix is a useful reference when creating user-defined roles, as it clearly shows which permissions are included in existing roles, helping you identify gaps and define appropriate access levels.
Jump To