StudyToCert

All certifications / NGFW Engineer / Lessons

Palo Alto Networks Certified Next-Generation Firewall Engineer NGFW-Engineer · Domain 2: PAN-OS device setting configuration

Administrator accounts: dynamic roles vs admin role profiles, API and CLI permissions

▶ Watch the overview video

Last reviewed September 30, 2026 · Leer en español

Every person or system that manages the firewall should have its own administrator account with the least privilege needed. Shared accounts make it impossible to tell who changed what, and over-privileged accounts turn one stolen password into a full compromise. Accounts are created under Device > Administrators, and each account has an authentication method and an administrative role. The role decides what the account can see and change in the web interface, the command-line interface (CLI) and the APIs.

Free account

Keep reading for free

Create a free StudyToCert account to read the rest of this lesson: 7 more sections, 7 key terms, a real-world example, an exam tip and self-check questions. Every lesson, lab and practice test is free with an account.

Sign up free Log in

Study NGFW Engineer for free
A week-by-week plan with every lesson, quizzes, checkpoint tests, a practice exam and hands-on labs.
Open the NGFW Engineer study plan