The Autodesk Account administration framework within manage autodesk lacks adequate permission granularity between the User and Secondary Admin roles. Organizations must elevate users to Secondary Admin simply so they can perform routine user and product management tasks. This creates unnecessary security exposure, increases compliance risk, and violates least privilege principles. Autodesk customers need an intermediate permission level that enables operational management without granting high-risk administrative authority. Current Issue Current ACC permission models force large organizations to assign Secondary Admin roles for routine tasks such as user management, product and entitlement assignment, group management, and running usage reports. However, the Secondary Admin role also grants high-risk capabilities, including user removal, role elevation, access to account-wide configuration, sensitive settings, and broader administrative visibility than is operationally necessary. This creates exposure to critical controls, increases the risk of accidental misconfiguration or improper access changes, makes it difficult to enforce least-privileged security, meet compliance requirements, and pass internal IT audits. There is no defined role between User and Secondary Admin to support controlled, practical user lifecycle and reporting responsibilities. Proposed Solution Create a new “User Management Admin” role - A purpose-built, limited-privilege role to perform operational user management. Capabilities should include: View and manage user accounts Edit external → user roles only (no elevation beyond User) Assign and unassign products Assign and unassign groups Access, view, and export usage and product reporting Restrictions should include: Cannot delete users Cannot promote users to Secondary Admin or higher Cannot modify billing, subscriptions, or account-level configurations Cannot modify security policies This role enables functional administration without compromising organizational security posture. Create a new “Download Access Admin” role - A role focused solely on installation access without administrative control. Capabilities should include: Download Autodesk products and services Manage installation packages where applicable Restrictions should include: Cannot manage user permissions This allows organizations to separate installation responsibilities from administrative control. Advantages Security & Compliance Supports zero-trust and least-privilege models Reduces risk of: accidental user removal inappropriate role elevation unauthorized access to billing and account configuration Improves alignment with SOC2, ISO 27001, and internal audit requirements Operational Experience Allows IT departments to safely delegate user onboarding/offboarding tasks Reduces administrative bottlenecks without expanding admin exposure Enables non-admin departments (VDC, PMO, BIM support, etc.) to manage licenses responsibly Reduced confusion over Secondary Admin responsibilities Autodesk Strategic Value Enhances Autodesk’s position as an enterprise-ready platform Helps large customers meet internal governance requirements Reduces friction for large customers managing complex environments Demonstrates Autodesk’s commitment to secure and flexible administration models The Ask We are requesting that Autodesk introduce more granular permissions in manage.autodesk.com by adding an intermediate User Management Administrator role (between User and Secondary Admin) and a separate Download Access Administrator role, enabling product assignment, group management, and reporting access without user deletion or role elevation, to reduce security risk and support least-privilege administration.
Show More