Composite roles are a group of functional roles combined from different functional categories.

By default, the following composite roles are available:

Composite Role SD-WAN Functional Role Cloud Web Security Functional Role Secure Access Functional Role Global Settings Functional Role
Enterprise Standard Admin SD-WAN Enterprise Admin Cloud Web Security Enterprise Admin Secure Access Enterprise Admin Global Settings Enterprise Admin
Enterprise Superuser SD-WAN Enterprise Superuser Cloud Web Security Enterprise Superuser Secure Access Enterprise Superuser Global Settings Enterprise Superuser
Enterprise Support SD-WAN Enterprise Support Cloud Web Security Enterprise Read Only Secure Access Enterprise Read Only Global Settings Enterprise Support
Enterprise Read Only User SD-WAN Enterprise Read Only No privileges No privileges Global Settings Enterprise Read Only
Enterprise Security Admin SD-WAN Security Enterprise Admin Cloud Web Security Enterprise Admin Secure Access Enterprise Admin Global Settings Enterprise Admin
Enterprise Security Read Only SD-WAN Security Enterprise Read Only Cloud Web Security Enterprise Read Only Secure Access Enterprise Read Only Global Settings Enterprise Read Only
Enterprise Network Admin SD-WAN Enterprise Admin Cloud Web Security Enterprise Read Only Secure Access Enterprise Read Only Global Settings Enterprise Admin

You can assign the above roles to a user, while creating a new Enterprise user. See Create New Admin User.

You can also map the composite role while configuring Single Sign on. See Configure Single Sign On for Enterprise User.

To view the existing composite roles along with the description, see Manage Composite Roles.

To create a custom composite role, see Create New Composite Roles.

You can also customize the role privileges of the functional roles. For more information, see Role Customization.