Enterprise Admin role unexpectedly downgraded to Group Admin: restore via Esper Support request
Android
If your Esper Console role has been unexpectedly downgraded from Enterprise Admin to Group Admin, you've lost access to enterprise-wide settings and features. This guide explains how to restore your Enterprise Admin privileges.
Before you begin
Role downgrades typically occur when:
- Another Enterprise Admin edited your role in Settings → User Management
- A bulk user import or directory sync (SCIM) overwrote your role assignment
- An automated API integration modified your role
Only an Enterprise Admin or Owner can change your role. If you're unsure why your role changed, contact Esper Support and include the approximate date and time you first noticed the downgrade.
How to restore your Enterprise Admin role
You must have an Enterprise Admin or Owner account to perform these steps.
- Log in to the Esper Console with an Enterprise Admin or Owner-level account.
- Go to Settings → User Management.
- Search for the affected user by name or email address.
- Click the user entry and select Edit.
- Change the Role field from
Group AdmintoEnterprise Admin. - Click Save. The change takes effect immediately.
- Ask the affected user to log out and log back in to the Esper Console and verify they now see Enterprise Admin access (full enterprise-wide settings, all device groups visible, and no scope restrictions).
If the role change doesn't work
- Role field is grayed out or missing: Confirm that your account has Enterprise Admin or Owner privileges. Only these roles can modify other users' roles.
- User still sees restricted access after the role is updated: Ask the user to clear their browser cache or try an incognito session. the Esper Console session may have cached the old role permissions.
- Role reverts after you restore it: This suggests an active SCIM sync, directory integration, or API automation is overwriting the role. Check Settings → Integrations for active directory or API integrations that may be resetting user roles automatically.
- You cannot identify what caused the original downgrade: Contact Esper Support and include the affected user's email address and the approximate date and time of the role change. Esper can review backend logs to identify who made the change.
Important notes
- Role changes are immediate and do not require a Blueprint push or any device-side action.
- The Owner role is the only role that outranks Enterprise Admin. Only an Owner can modify an Enterprise Admin's role.
- Esper's console does not currently display an audit log of role change events to users. If you need to identify who changed a role, contact Esper Support with details of the affected user and approximate date of the change.
Still need help?
If your Enterprise Admin role is still downgraded or continues to revert, submit a support request. Include the affected user's email address, the approximate date and time you first noticed the downgrade, and any information about active directory syncs or API integrations.
Please sign in to leave a comment.
Comments
0 comments