Permissions within user management should urgently be made more granular.
Currently, everyday administrative tasks cannot be sufficiently separated from security-critical permissions. It should be possible to grant a user specific rights to activate or deactivate other users, assign or remove licenses, and manage absences for other users without simultaneously giving them the ability to assign or modify roles, groups, or other permissions.
The assignment of roles and groups in particular is security-critical and should therefore be clearly separated from operational user management.
For us as a service provider, the current situation has a significant practical impact. We cannot delegate these everyday administrative tasks to our customers without granting them considerably more extensive permissions at the same time. As a result, we have to handle tasks such as license management and activating or deactivating users on behalf of our customers.
A granular separation of individual permissions within user management would significantly reduce administrative effort while also improving security.