User access and permissions

After provisioning is complete and sandboxes are bound, complete the following steps to provide Marketo Optimizer access for your team and users.

  1. Create a Marketo Optimizer product profile in the Admin Console (one-time/initial setup only).
  2. Add a user group in the Admin Console.
  3. Assign the product profile to the user group in the Admin Console.
  4. Add users to the new group in the Admin Console.
  5. Edit built-in roles or create a custom role with product permissions and the required Marketo Optimizer sandbox in Experience Platform.
  6. Add users or groups to roles in Adobe Experience Platform.

Configure the product profile config-profile

As an administrator, you can complete these tasks in the Adobe Admin Console, which is a central place to administer and manage your Adobe product licenses and users. In the Admin Console, you can create and manage users in a single location instead of within your various individual solutions. To learn more about its functions and capabilities, refer to the Admin Console overview page.

Access the Admin Console admin-console

Before you can use the Admin Console to administer users within your team, you need to ensure that you can access the Admin Console and have the appropriate permissions.

  1. As a system administrator, you should receive multiple emails from Adobe as part of the onboarding process.

    Locate the welcome email that provides the information about the organization name to which you have been granted access.

  2. Click the Get started link in your welcome email to navigate to the Admin Console.

    If you cannot find the email, open a browser directly to the Admin Console at https://adminconsole.adobe.com.

  3. Log in using your Adobe ID.

    Upon successful login, you see the Overview page of the Adobe Admin Console.

  4. If you have access to multiple organizations, ensure that you have logged in to the correct organization.

    To change your organization, click the organization name from the top right corner and choose the organization to which you need access.

  5. Select Administrators from the Users card to verify that you are a system administrator.

    Admin Console Overview page with Administrators selected from the Users card. {width="800" modal="regular"}

  6. Search by entering your Adobe ID email, username, first, or last name.

    • If your access is correctly configured, the search returns your record.

    • If the value in the ADMIN ROLE column shows System, you know that you (or the displayed user) are a system administrator.

Create the Marketo Optimizer product profile create-profile

When granting users access to an Adobe solution, you do not necessarily want to give them full access. Product profiles enable each solution to have its own set of user permissions. Use the Admin Console to assign product profiles.

For more information about using product profiles for user entitlements, see Manage product profiles for enterprise users in the Admin Console documentation.

Icon indicating that administrator access is required to complete this procedure. {width="30"} A system administrator or Experience Platform product administrator can perform the following steps from https://adminconsole.adobe.com.

  1. Select the Products tab.

  2. Open the Marketo Optimizer instance where you want to add the profile and click New profile.

  3. Enter a product profile name, such as Access.

  4. Click Next and then Save.

Add a user group add-user-group

A user group is a collection of users who are granted a shared set of permissions. You can add or remove users in your user group. The group permissions remain the same while the users within the group change.

For more information about how user groups are used to manage permissions, see Manage user groups in the Admin Console documentation.

Icon indicating that administrator access is required to complete this procedure. {width="30"} A system administrator can perform the following steps from https://adminconsole.adobe.com.

  1. Select the Users tab.

  2. Choose User Groups in the left navigation.

  3. Click New user group at the top right.

  4. Enter a name for the user group, such as Optimizer users and click Save.

    New user group dialog in the Admin Console with a group name entered. {width="600" modal="regular"}

Assign the product profile assign-profile

Icon indicating that administrator access is required to complete this procedure. {width="30"} A product administrator can perform the following steps from https://adminconsole.adobe.com.

  1. Click the user group that you created.

  2. Select the Assigned product profiles tab and click Assign profile.

  3. Click + and add each instance of the following products:

    • Adobe Marketo Optimizer - Access
    • Adobe Experience Platform - AEP-Default-All-Users
    • Adobe Experience Platform Data Collection - Default Data Collection All Access
    • Adobe Experience Platform - Default Production All Access

    Assigned product profiles tab in the Admin Console showing profiles added to a user group. {width="600" modal="regular"}

  4. Click Save.

Add users to the new group add-users

For information about user management, see Adobe Admin Console users in the Admin Console documentation.

Icon indicating that administrator access is required to complete this procedure. {width="30"} A system administrator or product administrator can perform the following steps from https://adminconsole.adobe.com. A product administrator can add only users that already exist in their organization.

  1. If the users are not already members of your organization, add each user:

    • Under Quick links, click Add users.

    • Enter the user’s email address and click Add as new user.

      Add new user dialog in the Admin Console with an email address entered. {width="600" modal="regular"}

    • Enter the first and last name, then click Save.

  2. Add each user to the group:

    • Click the user name.

    • In the user details page, scroll to User groups.

    • Click the More ( … ) icon on the left and choose Edit user groups.

    • Click the Add ( + ) icon below User groups.

      Edit user groups dialog in the Admin Console with a user group selected for a user. {width="600" modal="regular"}

    • Select the user group that you created previously and click Apply.

    • Click Save for the user changes.

Assign product permissions assign-product-permissions

Permissions are unitary rights that allow you to define the authorizations assigned to a product profile. Each permission is grouped under a capability, such as person journeys or content, representing functionalities in Marketo Optimizer.

The Permissions area of Adobe Experience Platform is where administrators can define user roles and access policies to manage access permissions for features and objects within a product application. In this app, you can create and manage roles, as well as assign the desired resource permissions for these roles. Permissions also allow you to manage the sandboxes and users associated with a specific role.

For more information about role permissions in Experience Platform, see Manage permissions for a role in the Experience Platform documentation.

  1. Go to experience.adobe.com.

  2. In the Quick access panel, select Permissions.

    note
    NOTE
    If you don’t see Permissions, you may need to click View all and select it from the available applications.

    Permissions application selected from the Quick access panel in Experience Platform. {width="700" modal="regular"}

Permission resources permissions

The following permission resources control access to channel configuration, content management, and person journey features in Marketo Optimizer:

IMPORTANT
Marketo Optimizer access requires that you enable a specific sandbox that is provisioned using the following naming convention: Mktoaep + Marketo Engage subscription prefix. For example, if your linked Marketo Engage subscription prefix is AcmeAssoc, the sandbox required for Marketo Optimizer access is MktoaepAcmeAssoc.
Category
Permission
Description
B2B Channel Configurations
View B2B Email Settings
View email settings (subdomains, PTR records, IP pools, suppression lists, seed lists, IP warm-up plans).
Manage B2B Email Settings
Configure email settings (subdomains, PTR records, IP pools, suppression lists, seed lists, IP warm-up plans). These settings are required before users can send emails.
Manage B2B Channels Configurations
Access to the Channels menu item in the left navigation and all channel configuration operations.
Manage B2B WhatsApp Presets
Create, view, and delete WhatsApp message presets and associated SMS settings.
B2B Journeys
Manage B2B Person Journeys
Access to the Person Journeys list and all person journey operations.
B2B Assets
View content templates
View content templates list and details.
Manage B2B Templates
Create, edit, and delete content templates.
View B2B Fragments
View content fragments list and details.
Manage B2B Fragments
Create, edit, and delete content fragments.
Publish B2B Fragments
Publish content fragments for use in templates, emails, and landing pages.
View B2B Assets
View the Assets library and asset file details.
Manage B2B Assets
Create, edit, and delete asset files.
View B2B Emails
View email messages.
Manage B2B Emails
Create, edit, and delete email messages.
Manage B2B Message Export
Export message reports under the Email section.
Journey Optimizer Library
Manage B2B Library Items
Add and delete saved expressions in the library.
Data Governance
Manage B2B Delete Usage Labels
View, create, and delete data usage labels (DULE) applied to datasets and schemas.
Sandbox Administration
Manage B2B Packages
Create, export, import, copy, and delete sandbox packages.

To provide support for external destinations in Marketo Optimizer, the following permissions are required:

Category
Permission
Description
Dashboards
View Standard Dashboards
View-only access to the Profiles, Destinations, and Segments dashboards. Also enables access to Dashboards in the left navigation and the Dashboards inventory and integrations tab.
Manage Standard Dashboards
Add custom attributes that are not yet in the data warehouse.
Destinations
View Destinations
View-only access to view available destinations in the Catalog tab and authenticated destinations in the Browse tab.
Manage Destinations
View, create, and delete destinations connections and destination accounts.
Activate Destinations
Activate data to active destinations. Either View Destinations or Manage Destinations is also required to access this function.
Activate Segment without Mapping
Activate audiences to existing destinations, without displaying the mapping step. Users can add and remove audiences in activation workflows, but cannot add or remove mapped attributes or identities. The View Destinations permission is also required to access this function.
Manage and Activate Dataset Destination
View, create, edit, and disable dataset export flows, as well as activate data to active datasets. The View Destinations permission is also required to access this function.
Destination Authoring
Ability to author destinations using the Adobe Experience Platform Destination SDK.
Data Governance
View Data Usage Policies
View-only access for data usage policies belonging to your organization.
Manage Data Usage Policies
View, create, edit, and delete data usage policies.
Data Ingestion
View Sources
View-only access to available sources in the Catalog tab and authenticated sources in the Browse tab.
Manage Sources
View, create, edit, and disable sources.
Profile Management
View Profile Settings
View-only access to all profile settings.
Manage Profile Settings
View and edit all profile settings.

Edit role permissions edit-role-permissions

For built-in or custom roles, you can decide at any time to add or delete permissions. If you modify a default or custom role, it impacts every user assigned to the role.

IMPORTANT
Marketo Optimizer access requires that you enable a specific sandbox that is provisioned using the following naming convention: Mktoaep + Marketo Engage subscription prefix. For example, if your linked Marketo Engage subscription prefix is AcmeAssoc, the sandbox required for Marketo Optimizer access is MktoaepAcmeAssoc.
NOTE
A product administrator with access to Experience Platform Permissions can perform these steps.

To change the permissions for a role:

  1. Select Roles in the left navigation.

  2. Click the Optimizer users role name.

  3. In the details page, click Edit at the top right.

    Role details page in Experience Platform Permissions with Edit selected. {width="800" modal="regular"}

    In the role editor, the Resources menu displays the list of resources that apply to the Experience Cloud - Platform powered applications.

  4. Select the sandbox provisioned for Marketo Optimizer access (Mktoaep<Marketo subscription prefix>).

    Sandbox selection list in the role editor showing the Marketo Optimizer sandbox available to add. {width="500" modal="regular"}

  5. Click the Add icon (+) for each of the functional resources.

    Role editor in Experience Platform showing the B2B Journeys resource added with permissions listed. {width="700" modal="regular"}

  6. Add the specific permissions for each of the resources, or select Add all.

  7. Click Save.

  8. Click Close to return to the details page.

Add users to a role add-users-to-a-role

Icon indicating that administrator access is required to complete this procedure. {width="30"} A system administrator or Experience Platform administrator can perform the following steps.

  1. Open the role details and select the Users tab.

    This tab displays a list of all users assigned to the role.

  2. Click Add users.

    Users tab in the role details page in Experience Platform with Add users selected. {width="800" modal="regular"}

  3. In the Add users dialog, locate and select the users that you want to add to the role.

    • You can use the Search tool to filter the list of users.

    • Select the checkbox for each user.

    Add users dialog in Experience Platform with user checkboxes selected to add to a role. {width="600" modal="regular"}

  4. Click Save when you have selected all the users that you want to add.

Add user groups to a role add-user-groups-to-a-role

For information about user management, see Adobe Admin Console users in the Admin Console documentation.

Icon indicating that administrator access is required to complete this procedure. {width="30"} A system administrator or Experience Platform administrator can perform the following steps.

  1. Open the role details and select the User groups tab.

    This tab displays a list of all user groups assigned to the role.

  2. Click Add Groups.

    User groups tab in the role details page in Experience Platform with Add Groups selected. {width="800" modal="regular"}

  3. In the Add groups dialog, locate and select the groups that you want to add to the role.

    • You can use the Search tool to filter the list of user groups.

    • Select the checkbox for each user group.

    Add groups dialog in Experience Platform with user group checkboxes selected to add to a role. {width="600" modal="regular"}

  4. Click Save when you have selected all the groups that you want to add.

Create a custom role create-a-custom-role

Icon indicating that administrator access is required to complete this procedure. {width="30"} A system administrator or Experience Platform administrator can perform the following steps.

  1. Select Roles in the left navigation and select Create role.

  2. In the Create new role dialog, enter a name for the role, such as B2B Marketers, and a description (optional).

  3. Click Confirm.

  4. Select the sandbox provisioned for Marketo Optimizer access (Mktoaep<Marketo subscription prefix>).

    Sandbox selection list in the role editor with the Marketo Optimizer sandbox selected. {width="500" modal="regular"}

  5. Add product permissions:

    To determine which product capabilities you want for the role, refer to the list of product permissions.

    In the Resources list on the left, locate the B2B items and click the Add (+) icon to add each attribute that you want to enable for the role.

    You can enter B2B in the search tool to filter the list for many of the B2B-related product permissions that apply to Marketo Optimizer.

    Role editor in Experience Platform with B2B resources filtered in the search field. {width="700" modal="regular"}

  6. Click Save at the top right.

  7. Go to the role details and select the User groups tab.

  8. Click Add Groups.

  9. Select the checkbox next to the user group that you created previously in the Admin Console.

  10. Click Save.

Your custom role is configured and users in the assigned group can now access the Marketo Optimizer capabilities you selected.

recommendation-more-help
marketo-optimizer-help-user-guide