How to create a WAS-only user

Document created by Parag Baxi on Oct 23, 2013Last modified by Dave Ferguson on Jan 6, 2020
Version 6Show Document
  • View in full screen mode

This article describes how to create a "WAS-only" user with no capabilities in other Qualys modules or products.  This is for the purpose of maintaining least privileges and is typical for developers or QA personnel who only use the Web Application Scanning product within Qualys.



  1. In the VM module, create an asset group with 0 IPs and call it "WAS only". This only needs to be done once.
  2. Under Users in the VM module, assign the new user the "Reader" role.
  3. On the Asset Groups tab, assign user the "WAS only" asset group.
    image (1).png
  4. On the Permissions tab, check "Manage VM module" only.  This is needed for historical reasons.  There's no need to check "Manage web applications" as this option is not actually related to WAS functionality.
  5. Open Administration under Utilities (located at the bottom of the main dropdown menu).
  6. Find the user in the list and select Edit.
  7. On the Roles & Scopes tab:


  • You can either check the "Allow user full permissions and scope" box to give the user full permissions in WAS or you can uncheck the box to assign roles as desired. More information about roles and permissions can be found at
  • If required for this user, uncheck "Allow user view access to all objects" and assign tags to set the scope of what the user can see. 
1 person found this helpful