Workspace ONE Access uses role-based access control to manage administrator roles. You assign the Super Admin, Directory Admin, and ReadOnly roles to directory user groups to manage administrative access to the region-specific Workspace ONE Access instance.

You assign the Workspace ONE Access roles to the Workspace ONE Access user groups.

Table 1. Workspace ONE Access Roles and Groups



Super Admin


Directory Admin


ReadOnly Admin



  1. In a Web browser, log in to the region-specific Workspace ONE Access instance in Region A by using the administration interface.
    Setting Value
    URL https://sfo01wsa01.sfo01.rainpole.local/admin
    User name admin
    Password sfo01wsa01_admin_password
    Domain System Domain
  2. On the main navigation bar, click Roles.
  3. Select the Super Admin role and click Assign.
  4. In the Users / groups search box, enter ug-wsa-admins@rainpole.local, select the group, and click Save.
  5. Repeat these steps to configure the Directory Admin and the ReadOnly Admin roles.