# Set User Privileges for Network Security Groups

Contract administrators and owner can create and manage NSGs within a data center. Normal contract sub-users need appropriate privileges to use and modify NSGs, without which they have read-only access and cannot provision changes. You can grant appropriate NSG privileges to contract sub-users via the **User Manager**.

If you turn off the privilege, your contract sub-users can manage the defined NSGs, provided they can access the respective data center.

To allow users to create NSGs, follow these steps:

1\. In the **DCD**, go to **Menu** > **MANAGEMENT** > **Users & Groups**.

2\. Select **Groups** tab in the **User Manager** window.

3\. Select the appropriate group to assign relevant privileges.

4\. In the **Privileges** tab, select the **Create Network Security Groups** checkbox to allow the group members to create and use it.

![Grant privileges to access NSGs](https://1737632334-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-MifAzdGvKLDTtvJP8sm%2Fuploads%2Fgit-blob-7509b02696b87a0cec131fec595b2b4ece1c8ec4%2Fset-privileges.png?alt=media)

{% hint style="info" %}
**Note:** You can remove the privileges from the group by clearing the **Create Network Security Groups** checkbox.
{% endhint %}

{% hint style="success" %}
**Result:** The group and its users are granted appropriate privileges.
{% endhint %}
