admin-url vs policy,json

Hi guys,

in doc openstack is this: "The admin endpoint allows modifying users and tenants by default...". But when i try modify or create user with "demo" role and --os-interface admin, it is not possible(HTTP 403) :(. When i try it with "admin" role, it works.

How does it work? Thanks...I am sorry for my English