ISSUE TYPE
COMPONENT NAME
CLOUDSTACK VERSION
SUMMARY
I have a Role named Domain Admin L2 with the Role Type of Admin and linked to the "admin l2" account in the ROOT domain (Csv rules attached).
The problem I encounter is that when I want to create a new account in the Sub-domain, let's call it ROOT/CS/Customer1, using the available default role named Domain Admin with Role Type DomainAdmin, an error appears stating 'can not create an account with access to more privileges they have themself.'
From the CSV i see the Domain Admin L2 role has more privileges than Domain Admin role.
What is wrong with what I'm doing?

Domain Admin_DomainAdmin.csv
Domain Admin L2_Admin.csv