Admin user can add/remove groups with security_admin roleDescriptionAdmin user can add/remove groups without security_admin roleSteps to Reproduce 1. Log in as admin user > Elevate to security admin2. Go to sys_user_group.do > Create testSecAdminGroup with security_admin role3. Remove security_admin elevation4. Go to sys_user.list and open joe employee5. Edit group > Add testSecAdminGroup in sluchbucketExpected - fails with message explaining that non-security_admin users cannot remove security_admin roleActual - adds group with security_admin role6. Edit roles > Remove testSecAdminGroup in sluchbucketExpected - fails with message explaining that non-security_admin users cannot remove security_admin roleActual - removes group with security_admin roleWorkaroundThis problem is currently under review and targeted to be fixed in a future release. Subscribe to this Known Error article to receive notifications when more information will be available.Related Problem: PRB1677730