I have a custom userrole called “FPNA”. They have “ADMINISTRATOR” roles in both the ADMINISTRATION and SYSTEM modules. I have given the FPNA role the ability to manage “ALL” users instead of selected roles. However when i log in as an FPNA user, and I click “create new user” I get an error that shows this trace: “Read access denied for member 'System.UserRoles' of object 'Administration.Account'” The userrole field is not editable in the new user screen. This doesn’t make any sense.
Give the FPNA user role as an administrator in the System module.
With the FPNA user already having admin roles for all the modules, I just re-imported the Admin role from scratch (redoing a few customizations), set all the exact same permissions back, and that did the trick. I guess something just got currupted at one point.
If this happens again the “one user role can edit which role”is in in the grantable role self associations[govened by the manage “ALL” users or selected roles part] and might be worth it to check in the DB if associations are in place