Purpose
To grant a user permissions to Configuration Manager through role based assignment using either direct membership or by group membership.
Description
- In the Configuration Manager console, navigate to 'Administration' > 'Overview' > 'Security' and right click on 'Administrative Users'.

- In the context menu, click on 'Add User or Group'.
- In the 'Add User or Group' window, click the Browse button.

- In the 'Select User, Computer, or Group' window, enter the user name or group name into the textbox.

- Click the 'Check Names' button to resolve the name from Active Directory.
- When finished, click the 'OK' button.
- In the 'Add User or Group' window, click the 'Add' button.

- On the 'Add Security Role' window, select the appropriate Security Role(s) from the list.
To administer Lenovo Patch, a user or group will need at minimum one of the 3 roles indicated above.

- Once all selections have been made, click 'OK'.
- In the 'Add User or Group' window, select the Security Scope option for 'All instances of the objects that are related to the assigned security roles'.

- Click 'OK'.