If an administrator creates a new administrative user,
by default, the new administrator must use a SecurID token to log in.
the administrator creating the new user must have at least a Super Admin role.
by default, the new user has permissions identical to the administrator creating the new user.
permissions granted to the new user can not exceed those of the administrator creating the new user.