You can create different administrators to manage the same global entitlements and global sessions in a federation access group.

For example, if your corporate global entitlements are in a single federation access group, you can create one administrator that can view and modify the global entitlements in that federation access group and another administrator that can only view the global entitlements in that federation access group.

In the following example, the administrator called Admin1 has the Administrators role on the federation access group called CorporateGlobalEntitlements, and the administrator called Admin2 has the Administrators (Read only) role on the same federation access group.

Administrator Role Federation Access Group
view-domain\Admin1 Administrators /CorporateGlobalEntitlements
view-domain\Admin2 Administrators (Read only) /CorporateGlobalEntitlements