User Management - Partner
The User Management feature allows you to manage users, their roles, service permissions, and authentication.

Users
To access the Users tab, use the following steps:
Add New User
In the Partner portal of the Orchestrator, you can add new users and configure the User settings. To add a new user, perform the following steps:
API Tokens
Any user can create tokens based on the privileges assigned to their user roles, except the Business Specialist users.
- Enterprise users can Create, Download, and Revoke tokens for them.
- Partner Super users can manage tokens of Enterprise users, if the Enterprise user has delegated user permissions to the Partner.
- Partner Super users can only create and revoke the tokens for other users.
- Users can download only their tokens and cannot download other users' tokens.
To manage the API tokens:
Roles
- Privileges – Privileges have a set of roles relevant to a service. A privilege can be tagged to one or more services. Users require privileges to carry out business processes. For example, a Customer support role in SD-WAN is a privilege required by an SD-WAN user to carry out various support activities. Every service defines such privileges based on its supported business functionality.
- Roles – The privileges from various categories can be grouped to form a role. By default, Orchestrator has the following roles for a Partner administrator:
Table 5. Roles Role SD-WAN Service Global Settings Service Partner Standard Admin SD-WAN Partner Admin Global Settings Partner Admin Partner Security Admin SD-WAN Security Partner Admin Global Settings Partner Admin Partner Network Admin SD-WAN Partner Admin Global Settings Partner Admin Partner Superuser Full Access Full Access Partner Business Specialist SD-WAN Partner Business Global Settings Partner Business Partner Customer Support SD-WAN Partner Support Global Settings Partner Support If required, you can customize the privileges of these roles. For additional information, see Service Permissions.
As a Partner, you can view the list of existing roles and the corresponding descriptions. You can add a new role, clone an existing role, edit or delete a custom role. You cannot edit or delete a default role.
To access the Roles tab:
Add Role
Service Permissions
- Starting from the 5.1.0 release, Role Customization is renamed as Service Permissions.
- Only an Operator Superuser can activate Service Permissions for a Partner Superuser. If you cannot view the Service Permissions option, contact your Operator.
Roles can be customized by changing the service permissions held by each role. You can customize both, default roles and new roles. Create Roles based on the selected default role. Define Operator, Partner, and Enterprise roles separately.
When customizing a role, you must select the user level and the role. Typically, Operator roles have more privileges by default, than Partners or Enterprise Customers. When creating a user, you must assign a role to the user. Any change to that specific role privileges immediately applies to all users assigned to that role. Role customizations only apply to one role at a time. For example, changes to Operator Standard Admin roles do not apply to Enterprise Standard Admin roles.
For additional information, see the topic Roles.
- The customizations performed at the Enterprise level override the Partner or Operator level customizations.
- The customizations performed at the Partner level override the Operator level customizations.
- Only when no customizations performed at the Partner level or Enterprise level, the customizations made by the Operator apply globally across all users in the Orchestrator.
To access the Service Permissions tab, use the following steps:
New Permission
To add a new permission, perform the following steps:
Authentication
To set the authentication mode, use the following steps:
Time-Based One Time Passcode (TOTP)
Release 7.0.0 introduces a new feature, the Time-based One-Time Passcode (TOTP) mechanism, for Two Factor Authentication (2FA). This feature replaces the current text-based 2FA mechanism (SMS) and mandates all future 2FA to use TOTP. Arista recommends selecting the TOTP authentication because it is more secure than the SMS-based authentication.
When a user enables TOTP under , the Orchestrator prompts all users who log in to either enroll (if not already enrolled) or provide the TOTP to complete authentication.
The procedure below explains the enrollment flow.














