
Administrators view in the Admin Panel allows adding and deleting administrator rights to the users.
Administrators can be added after clicking on the plus icon in the top right corner of the Administrators view.

Email address is the only field that is available in the dialog. After providing an email and confirming the save action, provided user should be able to access and use the Admin Panel.
Administrator rights can be taken away after clicking on the trash icon that appears after putting mouse over one of the rows with administrators. Please note, that it is impossible to take away the rights from current user.

Instead of promoting every user by hand, you can nominate one or more of your identity provider groups as admin groups. Members of those groups are granted administrator privileges automatically the next time they log in, and they lose the privileges again once the group is removed from the setting or the user leaves the group.
Admin Groups are available in the Enterprise Edition only.
The setting lives on the Defaults page of the Admin Panel. Add the group names that should receive administrator privileges.

The names you enter here have to match the groups that your OIDC provider actually sends to KKP. The match is exact and
case-sensitive, so Admins and admins are two different groups. A name that no upstream group corresponds to simply
never matches anyone.
The groups a user brings along from the identity provider are shown on the User Accounts page, which makes it easy to pick the right group name.

Administrators who received their privileges through a group are marked with a label in the Administrators list. Hovering over the label shows which group granted the privileges. These entries cannot be deleted from the list directly: to revoke the privileges, remove the group from the Admin Groups setting.

Some users are deliberately left out of this mechanism: