Enrollment Workflow Administrators
Members of the Enrollment Workflow Administrators role can perform the following operations.
- Subscription management
- User management
- CA management
- Certificate management
- Enrollment automation
- eForm enrollment
- CA Gateway management
Subscription management
Members of the Enrollment Workflow Administrators role cannot manage subscriptions.
| Operation | Authorized |
|---|---|
| Checking your subscriptions | ❌ |
| Assigning subscriptions to partitions | ❌ |
User management
Members of the Enrollment Workflow Administrators role cannot manage users.
| Operation | Authorized |
|---|---|
| Inviting users | ❌ |
| Managing roles | ❌ |
CA management
Members of the Enrollment Workflow Administrators role can perform the following CA management operations.
Certificate management
Members of the Enrollment Workflow Administrators role can perform all certificate management operations.
| Operation | Authorized |
|---|---|
| Browsing certificates | ✔ |
| Issuing a certificate from CSR | ❌ |
| Issuing a certificate in a PKCS #12 | ❌ |
| Changing the certificate status | ❌ |
| Downloading certificates | ✔ |
Enrollment automation
Members of the Enrollment Workflow Administrators role can only inspect the enrollment configuration.
eForm enrollment
Members of the Enrollment Workflow Administrators role can perform the following eForm enrollment operations
| Operation | Authorization |
|---|---|
| Creating eForm TLS enrollment workflows | ✔ |
| Requesting eForm TLS entities | ✔ |
| Approving and managing eForm TLS entities | ❌ |
| Downloading eForm TLS entity certificates | ✔ |
CA Gateway management
Members of the Enrollment Workflow Administrators role cannot perform the operation described in Managing CA Gateway credentials.