<div style="font-family: Arial, sans-serif; font-size: 14px;">Hi,</div><div style="font-family: Arial, sans-serif; font-size: 14px;"><br></div><div style="font-family: Arial, sans-serif; font-size: 14px;">I have the following authorization in place to prevent dangerous admin actions:</div><div style="font-family: Arial, sans-serif; font-size: 14px;"><br></div><div style="font-family: Arial, sans-serif; font-size: 14px;"><span> <!-- Dangerous: Factory reset --></span><div><span> <authorization></span></div><div><span> <name>system-configAbout-gui-deny</name></span></div><div><span> <decision>deny</decision></span></div><div><span> <action>http://midpoint.evolveum.com/xml/ns/public/security/authorization-ui-3#configAbout</action></span></div><div><span> </authorization></span></div><div><br></div><div><span> <!-- Dangerous: Clock change --></span></div><div><span> <!-- Dangerous: Kicking out logged-in users</span></div><div><span> This could arguably be used for "good", but will let admins also terminate sessions of other admins!!</span></div><div><span> --></span></div><div><span> <authorization></span></div><div><span> <name>system-configInternals-gui-deny</name></span></div><div><span> <decision>deny</decision></span></div><div><span> <action>http://midpoint.evolveum.com/xml/ns/public/security/authorization-ui-3#configInternals</action></span></div><div><span> </authorization></span></div><span></span><br></div><div style="font-family: Arial, sans-serif; font-size: 14px;"><span> <!-- Dangerous: Prevent account takeover --></span><div><span> <!-- Can't explicitly deny execution phase because user self-service password reset will need it --></span></div><div><span> <authorization></span></div><div><span> <name>shadow-credentials-password-value-modify-deny</name></span></div><div><span> <decision>deny</decision></span></div><div><span> <action>http://midpoint.evolveum.com/xml/ns/public/security/authorization-model-3#modify</action></span></div><div><span> <phase>request</phase></span></div><div><span> <object></span></div><div><span> <type>ShadowType</type></span></div><div><span> </object></span></div><div><span> <item>credentials/password/value</item></span></div><div><span> <!-- filter service accounts --></span></div><span> </authorization></span><br></div><div style="font-family: Arial, sans-serif; font-size: 14px;"><br></div><div style="font-family: Arial, sans-serif; font-size: 14px;"><span><div><span> <authorization></span></div><div><span> <name>user-credentials-password-value-modify-deny</name></span></div><div><span> <decision>deny</decision></span></div><div><span> <action>http://midpoint.evolveum.com/xml/ns/public/security/authorization-model-3#modify</action></span></div><div><span> <object></span></div><div><span> <type>UserType</type></span></div><div><span> <!-- employee archetypes --></span></div><div><span> <archetypeRef oid="..." /></span></div><div><span> ...</span></div><div><span> </object></span></div><div><span> <item>credentials/password/value</item></span></div><div><span> <!-- filter service accounts --></span></div><span> </authorization></span><br></span></div><div style="font-family: Arial, sans-serif; font-size: 14px;"><br></div><div style="font-family: Arial, sans-serif; font-size: 14px;">This authorization sits in a role <code>deny-dangerous-admin-func</code> that is included with all admin roles, including our superuser role. Note that this also prevents all password changes for anyone who holds an admin role, and the user has to de-escalate privileges before they can set any passwords via self-service.</div><div style="font-family: Arial, sans-serif; font-size: 14px;"><br></div>
<div style="font-family: Arial, sans-serif; font-size: 14px;" class="protonmail_signature_block">
<div class="protonmail_signature_block-user">
Om Bhallamudi<br>Proton AG
</div>
<div class="protonmail_signature_block-proton protonmail_signature_block-empty">
</div>
</div>
<div style="font-family: Arial, sans-serif; font-size: 14px;"><br></div><div class="protonmail_quote">
On Thursday, 2 July 2026 at 08:19, Fabian Noll-Dukiewicz via midPoint <midpoint@lists.evolveum.com> wrote:<br>
<blockquote class="protonmail_quote" type="cite">
<div style="direction: ltr; font-family: Aptos, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
Hi Steven,</div>
<div style="direction: ltr; font-family: Aptos, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<div style="direction: ltr; font-family: Aptos, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
this is quite simple. You can create an administrator role as copy of the default super user user role with the „authorization-3#all“ action. To avoid deletion, you add a second authorization block with the „authorization-model-3#delete“ action and decision
„deny“. The following screenshot shows my role configuration:</div>
<div style="direction: ltr; font-family: Aptos, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<img alt="image.png" id="id-542DBAA0-0172-4B95-A26D-0177B210342D" width="652" style="width: 652px; max-width: 100%;" class="proton-embedded" src="cid:542DBAA0-0172-4B95-A26D-0177B210342D"></div>
<div style="direction: ltr; font-family: Aptos, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<div style="direction: ltr; font-family: Aptos, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
Kind regards,</div>
<div style="direction: ltr; font-family: Aptos, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
Fabian</div>
<div style="direction: ltr; font-family: Aptos, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<div style="direction: ltr; font-family: Aptos, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
--</div>
<div id="ms-outlook-mobile-signature" style="color: inherit; background-color: inherit;">
<p class="MsoNormal" style="margin: 0cm; font-family: Calibri, sans-serif; font-size: 11pt;">
<span style="font-family: Verdana, sans-serif; font-size: 10pt; color: black;"><b>Fabian Noll-Dukiewicz</b></span></p>
<p class="MsoNormal" style="margin: 0cm; font-family: Calibri, sans-serif; font-size: 11pt;">
<span style="font-family: Verdana, sans-serif; font-size: 10pt; color: black;"><i>Spezialist Identity & Access Management | Geschäftsführer</i></span></p>
<p class="MsoNormal" style="margin: 0cm; font-family: Calibri, sans-serif; font-size: 11pt;">
<span style="font-family: Verdana, sans-serif; font-size: 10pt; color: black;">Tel.: +49 152 244 63 211</span></p>
<p class="MsoNormal" style="margin: 0cm; font-family: Calibri, sans-serif; font-size: 11pt;">
<span style="font-family: Verdana, sans-serif; font-size: 10pt; color: black;">Email: fabian.noll-dukiewicz@veryfy.gmbh</span></p>
<p class="MsoNormal" style="margin: 0cm; font-family: Calibri, sans-serif; font-size: 11pt;">
<span style="font-family: Verdana, sans-serif; font-size: 10pt; color: black;">Web:
</span><span style="font-family: Verdana, sans-serif; font-size: 10pt; color: rgb(5, 99, 193);"><u><a href="https://veryfy.gmbh" data-outlook-id="fe8cd8e0-caa3-4902-b5af-c404057f6eee" style="color: rgb(5, 99, 193); margin-top: 0px; margin-bottom: 0px;" target="_blank" rel="noreferrer nofollow noopener">https://veryfy.gmbh</a></u></span><span style="font-family: Verdana, sans-serif; font-size: 10pt; color: black;">
</span><span style="color: black;"> </span></p>
<p class="MsoNormal" style="margin: 0cm; font-family: Calibri, sans-serif; font-size: 11pt;">
</p>
</div>
<div id="mail-editor-reference-message-container" style="color: inherit; background-color: inherit;">
<div class="ms-outlook-mobile-reference-message skipProofing">
</div>
<div class="ms-outlook-mobile-reference-message skipProofing" style="text-align: left; padding: 3pt 0in 0in; border-width: 1pt medium medium; border-style: solid none none; border-color: rgb(181, 196, 223) currentcolor currentcolor; font-family: Aptos; font-size: 12pt; color: black;">
<b>Von: </b>midPoint <<a href="mailto:midpoint-bounces@lists.evolveum.com" rel="noreferrer nofollow noopener" style="word-break: break-word;">midpoint-bounces@lists.evolveum.com</a>> im Auftrag von Ashwill, Steven L via midPoint <<a href="mailto:midpoint@lists.evolveum.com" rel="noreferrer nofollow noopener">midpoint@lists.evolveum.com</a>><br>
<b>Datum: </b>Mittwoch, 1. Juli 2026 um 16:13<br>
<b>An: </b><a href="mailto:midpoint@lists.evolveum.com" rel="noreferrer nofollow noopener">midpoint@lists.evolveum.com</a> <<a href="mailto:midpoint@lists.evolveum.com" rel="noreferrer nofollow noopener">midpoint@lists.evolveum.com</a>><br>
<b>Cc: </b>Ashwill, Steven L <<a href="mailto:sashwill@uillinois.edu" rel="noreferrer nofollow noopener">sashwill@uillinois.edu</a>><br>
<b>Betreff: </b>[midPoint] disable "DeleteAll" options in production<br>
<br>
</div>
<div class="PlainText" style="font-size: 11pt;">Is there a way to remove the option or the permissions that allow a super user to "Delete All Objects" or "Delete all Shadows" from the repository menu and other screen where that may exist. There is no reason
that I can think of where we would want to do this in production and unfortunately it has happen by accident twice in the last 2 years.<br>
<br>
<br>
STEVEN L ASHWILL<br>
Software Engineer Coordinator<br>
Administrative Information Technology Services<br>
University of Illinois at Urbana-Champaign<br>
50 Gerty Drive | M/C 673<br>
Champaign, IL 61820<br>
217.265.6337 | <a href="mailto:sashwill@uillinois.edu" rel="noreferrer nofollow noopener">sashwill@uillinois.edu</a><br>
<a href="http://www.aits.uillinois.edu" data-outlook-id="a1b93ca0-8e7c-4377-86a5-2c913c33b4d6" target="_blank" rel="noreferrer nofollow noopener">www.aits.uillinois.edu</a><br>
<br>
<br>
<br>
Under the Illinois Freedom of Information Act any written communication to or from university employees regarding university business is a public record and may be subject to public disclosure. <br>
<br>
<br>
_______________________________________________<br>
midPoint mailing list<br>
<a href="mailto:midPoint@lists.evolveum.com" rel="noreferrer nofollow noopener">midPoint@lists.evolveum.com</a><br>
<a href="https://lists.evolveum.com/mailman/listinfo/midpoint" data-outlook-id="b5927554-3a00-43c3-88ab-5ec9f85e23a4" target="_blank" rel="noreferrer nofollow noopener" style="word-break: break-word;">https://lists.evolveum.com/mailman/listinfo/midpoint</a><br>
</div>
</div>
</blockquote><br>
</div>