Troubleshooting a Super User Target Denial

Troubleshooting a Super User Target Denial requires identifying whether the problem is in plugin visibility, target eligibility, the short-lived handoff, or the separate frontend session before changing configuration.

Diagnostic procedure

  1. Confirm the target’s effective groups/permissions include core.admin.
  2. Do not remove Super User privileges merely to bypass QCUI’s security rule during an active support session.
  3. Use the target’s own authorized administrator login for Super User testing, or test with an appropriate non-Super-User account.

Keep the layers separate

This denial is driven by the target’s core.admin authorization. Keep privileged-account testing in normal administrator authentication rather than troubleshooting the handoff/session layers.

Information to preserve

Record the target username and effective Super User/core.admin authorization. Do not strip permissions just to produce a successful QCUI test.

When to escalate

If Troubleshooting a Super User Target Denial persists after the documented layer is verified, stop creating repeated handoffs and preserve the exact error/context. A private support case should include version/state evidence but never passwords, session cookies, MFA secrets, or raw QCUI tokens.

When to escalate

If Troubleshooting a Super User Target Denial persists after the documented layer is verified, stop creating repeated handoffs and preserve the exact error/context. A private support case should include version/state evidence but never passwords, session cookies, MFA secrets, or raw QCUI tokens.


Community Discussion

Want to compare support workflows, share practical tips, or discuss how you use this QCUI feature? Visit the QC User Impersonation Community. For private support, bug reports, account-specific issues, or feature requests, use the QuantaCade support system.