For super user, you have to have a separate user from identity store which will have all following roles assigned:
1. Infrastructure administrator rights for all tenants.
2. Tenant administrator rights for all tenants.
3. Fabric group administrator rights for all fabric groups, in all tenants.
If you find this or any other answer useful please mark the answer as correct or helpful
https://communities.vmware.com/people/greco827/blog