Configuring FortiClient group-based administration
You can divide administration of FortiClient agent groups among several group administrators. A group administrator is assigned particular FortiClient groups and optionally also has access to ungrouped clients. With the assigned FortiClient agents, the group administrator can
• monitor status
• retrieve, modify and deploy configurations
• change group membership (among assigned groups only).
Any FortiManager administrator who does not have the Super_User administrator profile can become a FortiClient Manager group administrator. The permissions settings of the profile apply, except that FortiClient group administrators
• cannot modify FortiClient Manager global settings
• cannot create or edit FortiClient groups
• cannot delete a FortiClient agent
• cannot perform the Search/Add Client function or add a temporary client to the managed clients list
• cannot access clients that belong to another administrator’s assigned groups
• cannot set the Roaming status of a FortiClient agent.