Workspace ONE Access uses role-based access control to manage administrator roles. You assign the Super Admin, Directory Admin, and ReadOnly roles to directory user groups to manage administrative access to the cross-region Workspace ONE Access cluster.

You assign the Workspace ONE Access roles to the Workspace ONE Access user groups.

Table 1. Workspace ONE Access Roles and Groups



Super Admin


Directory Admin


ReadOnly Admin



  1. In a Web browser, log in to the Workspace ONE Access cross-region cluster by using the administration interface.
    Setting Value
    URL https://wsa01svr01.rainpole.local/admin
    User name configadmin
    Password wsa01svr01_configadmin_password
    Domain System Domain
  2. On the main navigation bar, click Roles.
  3. Select the Super Admin role and click Assign.
  4. In the Users / groups search box, enter ug-wsa-admins@rainpole.local, select the group, and click Save.
  5. Repeat these steps to configure the Directory Admin and the ReadOnly Admin roles.