# Set User Privileges for CDN

Users need appropriate privileges to create and manage CDN distributions. Cloud CDN has a new group privilege called **Access and manage CDN**. This privilege must be enabled for a group so that the members of this group inherit it through group privilege settings and can manage the CDN distributions.

{% hint style="info" %}
**Prerequisite:** Make sure you have one or more **Groups** in the **User Manager**. To create one, see [<mark style="color:blue;">Create a group</mark>](https://docs.ionos.com/sections-test/guides/set-up-ionos-cloud/management/identity-access-management/user-management#create-a-group).
{% endhint %}

To set user privileges to manage CDN distributions, follow these steps:

1. In the **DCD**, go to **Menu** > **Management** > **Users & Groups**.
2. Select the **Groups** tab in the **User Manager** window.
3. Select the appropriate group to assign relevant privileges.
4. In the **Privileges** tab, select **Access and manage CDN**.

![CDN set user privileges](https://1737632334-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-MifAzdGvKLDTtvJP8sm%2Fuploads%2Fgit-blob-35359e5d680f4a3ee8249a1c89d60b743295252a%2Fcdn-set-user-privileges.png?alt=media)

{% hint style="info" %}
**Note:** You can remove the privileges from the group by clearing **Access and manage CDN**.
{% endhint %}

{% hint style="success" %}
**Result:** The privilege to manage CDN distributions is granted to all the members in the selected group.
{% endhint %}

## Revoke user privileges

You can revoke a user's **Access and manage CDN** privilege by removing the user from all the groups with this privilege enabled.

{% hint style="warning" %}
**Warning:** You can revoke a user from this privilege by disabling **Access and manage CDN** for every group the user belongs to. In this case, all the members in the respective groups would also be revoked from this privilege.
{% endhint %}

To revoke this privilege from a contract administrator, disable the administrator option on the user account. After performing this action, the contract administrator will become a contract user, and the privileges that were set up for the user before becoming an administrator will then be in effect.
