---
locale: "en"
updated_at: "2026-07-16T16:47:05.523Z"
canonical: "https://www.isdecisions.com/en/fileaudit/docs/guides/configuration/set-up-fileaudit-permissions"
---

# Set up FileAudit permissions

Delegate console access to users or groups without admin rights

## Before you begin

FileAudit permissions let you give specific users or groups access to console features without granting them full administrative rights. You decide, per account, which features are allowed or denied. 

> **Note**
>
> These permissions control the FileAudit console only: they **do not change** file system permissions on your audited resources.

Before you start, make sure you have:

- The [Configure permissions](/fileaudit/docs/reference/settings) right in FileAudit.
- An existing Windows user or group to delegate access to.

## Grant access to a user or group

1. In the **Settings**** > ****Permissions** view, click **Add a user** or **Add a group**.
  ![Settings configuration User and Groups](https://a.storyblok.com/f/122374/688x553/a52d1289ed/settings-configuration-users-groups.png)
2. In the Microsoft account selector, type the account name and click **Check Names**. Once the name is validated, click **OK**.
  ![Permissions - Add a user](https://a.storyblok.com/f/122374/934x612/9bf15a2b13/permissions-add-user.png)
3. A panel opens on the right of the Permissions view. Set each feature to **Allow** or **Deny** for this user or group.
  ![](https://a.storyblok.com/f/122374/1286x774/419348cdf4/settings-permissions.png)
4. Save your changes. Denied features are immediately greyed out in the FileAudit hub for that account.
  ![Tile denied](https://a.storyblok.com/f/122374/597x558/b49ac98499/hub-denied.png)
5. To confirm the result, sign in as the delegated user, or ask them to, and open the FileAudit hub. The tiles for any denied feature must appear disabled, and allowed features must be accessible.

For what each feature controls, see [Permissions](/fileaudit/docs/reference/settings#permissions) Reference.

## Troubleshooting

> **Note**
>
> ⚠️** Important**
> Never delete the default administrators rule. Doing so can **lock everyone out** of the Permissions section, with no way back through the console.

If a user is unexpectedly denied a feature, check every account they belong to. FileAudit follows the same rule as Windows: a single **Deny** on any group overrides an **Allow** elsewhere. Full resolution logic is documented in [Permissions](/fileaudit/docs/reference/settings#permissions) Reference.
