Microsoft Project Online is end of life: MS Project Online retires September 30, 2026. Seamlessly migrate your .mpp portfolios to ProjectLibre Cloud.Learn Migration Path

ProjectLibre Academy · Administration & Configuration

Administration & Security

How the Administration modal governs users, teams, roles and project access, with a role-gated control plane and setup checklist.

See also: Administration & General Configuration · User Management · RBAC · Personal Settings & Avatar · Portfolio · Assigning Resources · My Work & My Team.

Watch: User Management (~3:30) — same video as User Management; framed here as Administration & Security.

Admin modal as the security control plane

Access depends on role. Opening Administration shows a modal whose tabs and controls differ based on your signed-in role. For administrators the tabs are: Users · Teams · Roles · Licenses · Payment · Company. Footer actions on every tab: Cancel · Apply · Save.

Think of Users / Teams / Roles as the identity and RBAC surface; Licenses / Payment / Company as finance and sign-up. For timesheet/approval project options that also sit near Administration teaching, see General Configuration.

Administration modal — Users tab with password leave-empty placeholder Left nav Administration → modal on Users (role-gated control plane)

Open Administration from the left nav

  1. In the left sidebar, click Administration.

  2. The Administration modal opens (demo lands on Users).

  3. Confirm you are signed in with an admin-capable role — the UI is role-gated.

Step-by-step chrome and discard-unsaved dialog also appear under Administration modal and User Management — Open Administration.

On the Users tab: list columns Email · First Name · Last Name; toolbar + Add User (and trash to delete).

Security-relevant fields when adding a user

  1. First Name, Last Name, Email.

  2. Password — new users: placeholder Enter a password (show/hide eye). Existing users: Leave empty to keep current.

  3. Resource — default + Create new resource, or associate the login with an existing resource instead.

  4. Roles (dual-list Active Selection / Search) — default: project manager / UI Project_Manager; drag e.g. Team_Member when needed.

  5. Teams (same dual-list) — optional; demo puts a user on IT Team and India.

  6. Apply / Save.

Add User form with Enter a password placeholder + Add User — First/Last/Email + Enter a password

User form Resource section Create new resource Resource → + Create new resource (or associate existing)

Roles dual-list with Team_Member in Active Selection Roles dual-list — demo Team_Member in Active Selection

User Teams dual-list IT Construction Marketing India User Teams assignment — IT / Construction / Marketing / India

Detailed guidance: Add user · Add user to a team.

Teams — portfolio access boundary + assignment filter

The Teams tab builds org groups (+ Add Team, Team Name, Resources dual-list). Demo: India Active members Tayler, Kai, Kristen; add Connor and Sidney, then Save.

  1. Assignment filter — when a project manager assigns resources, they see team members only, not the entire pool.

  2. Portfolio visibility limit — a person on a project team (customer example) sees only that project in the portfolio.

  3. Override — Portfolio_Manager still sees all projects despite team limiting. Deep dive: User Management — Teams.

Teams tab IT Team with Resources dual-list Teams tab — IT Team Resources dual-list

India team Active Selection Tayler Kai Kristen India team — Active: Tayler, Kai, Kristen (then add Connor / Sidney)

Roles & privileges — inheritance summary

On Roles: + Add Role, duplicate/copy, delete; field Role Name. Listed roles include Administrator, Project_Manager, Customer Role, Portfolio_Manager, Team_Member, Resource_Manager, Team_Member Limited Views.

Inherited Roles (dual-list): demo shows Administrator inherits Portfolio_Manager + Resource_Manager (badge 2); Project_Manager inherits Team_Member (badge 1). privileges are inherited as they go up — Team Member = least privileges; Project Manager = next level up.

  • GENERAL — Authenticated User (checked; TM tag / lock cues).

  • VIEW ACCESS — per-surface checkboxes (Home, Dashboard, Portfolio, Projects, Resource Pool views, Project: Gantt / Spreadsheet / Usage / Network / WBS, Predecessors, Successors, Assignments, Calendar, Reports, …) with TM / PM tags and lock icons.

  • ADMIN ACCESS (bottom of scroll) — Users · Teams · Roles · Admin Portfolio (PM tags). More groups exist below the fold (not fully captured).

Role capability summary: Administrator can add/delete; Project Manager manages/deletes their projects; Portfolio Manager sees all projects; Team Member (good for contractors) sees only their project and only their tasks on login; Resource Manager is for setting this structure up.

Roles tab Administrator Inherited Roles Roles — Administrator Inherited Roles (Portfolio_Manager + Resource_Manager)

Project_Manager Privileges VIEW ACCESS grid Privileges — VIEW ACCESS grid for Project_Manager

Privileges ADMIN ACCESS Users Teams Roles Admin Portfolio ADMIN ACCESS — Users · Teams · Roles · Admin Portfolio

Project_Manager inherits Team_Member Project_Manager Inherited Roles → Team_Member (least → next level up)

Project-level access (Manage Access)

Org roles and teams are only half of access. Which projects someone can open — and whether they act as Project Manager, Team Member, or another project role — is controlled from Portfolio → Manage Access.

Licenses · Payment · Company

These Administration tabs are now walked in the Admin Menu tour under Administration modal — Licenses (PM vs Team Member seats), Payment, and Company (currency, Timesheet, DCMA thresholds, scoring). This Security section keeps Users · Teams · Roles · Manage Access as the primary RBAC lab; use the modal chapter for finance / company-standards depth.

First-time security setup checklist

A practical first-pass order for a new Cloud tenant (security angle):

  1. Sign in as Administrator → open Administration.

  2. Review built-in Roles / Inherited Roles (least-privilege Team Member vs Portfolio Manager override).

  3. Create Teams that match how you want to limit portfolio visibility and assignment pools.

  4. Provision each person: email + password + role + optional team → Save.

  5. For each project, finish access in Portfolio Manage Access (details).

  6. Point new users at Personal Settings & Avatar (their own Options — not org admin).

Expanded checklist with product wording: User Management — First-time setup checklist · How it fits together.

Watch the Administration & Security video

User Management (~3:30) — identical YouTube ID to the User Management chapter. Use this hub for security framing; use User Management for the full RBAC lab.