Support
Milestone XProtect Users, Roles and Camera Permissions
VMS Permissions
Summary
Follow the four stages below to diagnose a user cannot see required cameras or has more XProtect access than intended without losing evidence, configuration or device ownership.
Applies to
- Milestone XProtect users and groups
- Least-privilege VMS handover
Difficulty and time
Difficulty: Advanced
Estimated time: 25 to 60 minutes
What you will need
- The exact model and current firmware or app version
- Administrator access where authorised
- A photo or screenshot of the current status
- One controlled test case and its exact time
What this guide covers
- Preserve and reproduce the fault
- Open the correct diagnostic screen
- Correct the proven cause
- Verify and document the result
Use this page when a user cannot see required cameras or has more XProtect access than intended. It includes the menu or screen to look for, the status that matters and a repeatable proof test.
Exact labels can differ between recorder, controller, app and firmware versions. If the named screen is not present, do not guess at destructive options; note the model and current version for support.
Before you start
Protect the current system and record a baseline before changing anything.
- Write down the exact symptom: cameras, playback or export are missing, or a user can reach administrative functions they should not have.
- Photograph the current status, error text, wiring or timeline as applicable.
- Record the last known working time and anything changed immediately before the fault.
- Export or document current role assignments before bulk changes.
Test permissions with the real user, not only an administrator preview
Overbroad VMS access exposes live video, recordings and exports. Apply least privilege and follow privacy policy.
If the required option is missing or the result does not match this guide, stop and identify the exact model before continuing.
What usually causes this
- User is not in the intended role
- Camera/device group is excluded
- Playback/export privilege is missing
- Legacy role grants too much access
Step 1: Preserve the current state and reproduce the fault
Begin with a repeatable baseline so you know whether a later change genuinely helped.
- Reproduce the problem once and record: cameras, playback or export are missing, or a user can reach administrative functions they should not have.
- Note whether every device or user is affected, or only one.
- Compare one working path with the failing path if a comparison exists.
- Export or document current role assignments before bulk changes.
Step 2: Open the correct screen and inspect the evidence
The primary diagnostic location is Management Client > Site Navigation > Security > Roles, then Users and Groups. Do not change anything until the displayed state is recorded.
- Open Management Client > Site Navigation > Security > Roles, then Users and Groups. Menu wording can vary by model and firmware; use the nearest equivalent label.
- Identify whether the user is Basic, Windows/AD or another supported identity.
- Review effective role membership and device permissions.
- Check live, playback, sequence, export, audio and administrative privileges separately.
Step 3: Correct only the cause you proved
Use the matching correction below. Make one change, save it, then repeat the same test.
- Create role-based groups around actual duties rather than one-off broad exceptions.
- Grant only required devices and functions.
- Assign users/groups and remove conflicting legacy roles.
- Document privileged accounts and use named administrators instead of shared logins.
Step 4: Verify, monitor and document the handover
A saved setting is not proof. Test the real outcome locally first, then test any app, cloud or client path separately.
- Sign in as the actual test user.
- Confirm intended cameras and playback are visible.
- Test export/audio/PTZ only if granted.
- Confirm an ungranted camera and administrative action remain unavailable.
Controlled support test
Situation: The reported symptom was: cameras, playback or export are missing, or a user can reach administrative functions they should not have.
Solution used: The current state was recorded in Management Client > Site Navigation > Security > Roles, then Users and Groups, one matching correction was made, and the same test was repeated.
Why this was chosen: This separated the proven cause from unrelated settings.
Installation notes: The final screenshot and test time were saved with the handover record.
Official reference used for this guide
Menu names differ between releases. Confirm model-specific behaviour in Milestone XProtect Administrator Manual before firmware, reset, storage or security-sensitive work.
Common mistakes
- Changing several settings before repeating the original test.
- Using a factory reset, initialise or format option as an early troubleshooting step.
- Treating an app symptom as proof that the local hardware or recording has failed.
- Failing to record the model, version, exact error and test time before escalation.
- Assuming similar-looking models use identical menus or features.
Troubleshooting table
| Symptom | What to check | What to do next |
|---|---|---|
| cameras, playback or export are missing, or a user can reach administrative functions they should not have | wrong identity source, missing role membership, device group excluded, privilege not granted or conflicting broad role | Open the named diagnostic screen, record the displayed state and use the matching correction above. |
| The named menu is not visible | Different firmware, permissions or model capability | Do not substitute a destructive menu. Capture the model and version and use its official manual. |
| The change saves but the fault remains | The selected cause was not the root cause | Undo the change if appropriate, return to the baseline and compare the failing path with a working one. |
| Local test works but app or client test fails | Account, permission, cloud or remote-network path | Keep the proven local configuration and diagnose the remote path separately. |
| Problem returns later | Intermittent power, cable, storage, network or schedule condition | Record the new failure time and status; correlate it with logs, events and the last known working interval. |
When to contact support
Contact SecurityWholesalers support when effective role membership appears correct but the actual user session still has wrong device/function access.
Send the order number if available, exact model, firmware or app version, screenshot of Management Client > Site Navigation > Security > Roles, then Users and Groups, the failure time, and the result of the local proof test.
Related support guides
- Milestone XProtect Support Guides - Browse every guide in this support area.
- All Technical Support Guides - Return to the complete support library.
Related buying guides
- CCTV Buying Guide - CCTV system-planning guide.
Relevant product categories
- Milestone Products - Milestone licences and products.
Still stuck?
Need help choosing or setting up a system? Contact SecurityWholesalers support with your order number, product model and a clear description of the issue.
Frequently asked questions
-
Where should I click first for Milestone XProtect user permissions?
Start at Management Client > Site Navigation > Security > Roles, then Users and Groups. Record the existing state before changing it because labels and available options can vary by model and firmware.
-
What should I look for on that screen?
Look for identity type, role membership, device groups and separate live/playback/export/admin privileges.
-
What must I avoid changing during the first check?
Overbroad VMS access exposes live video, recordings and exports. Apply least privilege and follow privacy policy.
-
How do I prove the correction worked?
The real user should complete intended tasks and fail an explicitly ungranted camera/action.
-
Why might my menu names look different?
Recorder, controller, camera, app and firmware releases can use different labels. Use the closest equivalent only when its function is clear; otherwise record the model and version for support.
-
Should I factory-reset the device?
Not as an early step. A reset may erase users, network settings, recording configuration, licences or cloud ownership. Back up the configuration and confirm the recovery plan first.
-
What should I send technical support?
Send the exact model and version, screenshot of Management Client > Site Navigation > Security > Roles, then Users and Groups, exact error text, failure time, what changed before the fault and the result of the controlled local test.
-
Can configuration changes recover data or events that were never recorded?
No. A correction can restore future operation, but it cannot recreate footage, alarm events or access transactions that were never stored.
















