uipath-admin
UiPath Admin
Administrative operations through uip admin for Identity Server, Authorization, OMS, IP Restriction, and Audit.
When to Use
- Identity: Users, groups and membership, robot accounts, external apps and credentials, PATs, SMTP, OAuth2 scope discovery, and human or robot onboarding.
- Authz: Custom roles, assignments, permission catalogs, effective access, and ad-hoc grants. Role scopes are
Organization,TenantGlobal,Tenant, andProject; assignments may also useFolderorApp. - OMS: Current organization, tenant lifecycle, service provisioning, operation polling, and region discovery. The CLI cannot create or delete organizations.
- IP Restriction: Allowlist entries, enforcement, bypass rules, and
ip-restriction my-ipfor public-IP questions and safety checks. - Audit: Use
uip admin audit, neveruip or audit-logs, for organization or tenant audit events, sources, targets, types, queries, login history, membership/license activity, tenant activity, investigations, and exports.uip or audit-logsis Orchestrator-operational audit and belongs touipath-platform. - Troubleshooting: Use the diagnose capability index and identity troubleshooting guide for access, authentication, identity, tenant operations, provisioning, robot authentication, SMTP, PAT, external-app, or IP-lockout symptoms.
For audit availability, run uip admin audit <scope> sources; discover live catalogs instead of relying on memory. Route org versus tenant with audit-workflow-guide.md → Audit scope disambiguation and Rule 23. Natural-language investigations may cover resource changes/deletions, sign-ins, tenant changes, compliance windows, and cross-scope requests; run once per requested scope and combine results.
Troubleshooting routes: access denied — 403, "role not taking effect", and cross-service role confusion are one scenario → resolve the principal, check effective access, look up the required permission, then branch on missing permission versus mis-scoped grant (Playbook 1, failure modes → Access denied); suspicious logins → organization audit (Playbook 2); IP lockout → my-ip, ranges, and enforcement (Playbook 3); PAT/external-app failure → expiry, scopes, and revocation audit (Playbook 4). SMTP uses smtp get and smtp test; poll stuck tenant operations; for provisioning no-ops check platform-pinned services; distinguish robot identity issues from credential-model issues.