Administrators can create roles with permissions and assign them to users.
ePO - SaaS provides these default roles:
ePO - SaaS Administrator
Trellix Account Administrator
Administrators have full rights throughout the system. Regular users can be assigned role-based permissions to define their access levels in ePO - SaaS.
ePO - SaaS provides the option to assign the appropriate access to users. For example, a user might want to view your custom query, but doesn't need to make any changes to it. Another user might want to manage endpoints, but doesn't need to analyze cloud application use. Limiting access to features makes sure that only the users you choose have access or can make changes to your data. You can delegate the work of administrating ePO - SaaS to more administrators without giving them more access than they want or need.
Permissions are grouped into roles that can be assigned to multiple users. Users can also be assigned to multiple roles, which give them an accumulation of permissions granted by each of the roles. Some roles are provided for you, but you can also customize a role by creating or duplicating a role. You can assign a role to any number of users when the right permissions are selected.
Users can be assigned any number of roles. An effective permission is a combination of all roles assigned to the user. For example, to allow users to deploy products, these roles must be assigned.
Tag management roles
View and edit policies/task roles of products for which the user needs to be granted access for deployment
System Tree permissions - view or edit
Administrators can't assign or unassign roles for their own accounts.
From ePO - SaaS, select Menu → Configuration → Users & Roles.
Next to Roles, click Add Role.
In the Role Name field, type the name of the role you want to create.
From the Unassigned Permissions, select Trellix ePO - SaaS and enable these options:
Select Policy and then enable: File and Removable Media Protection: View and change policies and File and Removable Media Protection: View policies.
Select Systems and then enable: File and Removable Media Protection: View recovery keys.
Select Reporting and then enable: File and Removable Media Protection: View properties
Select View Queries & Reports created by users to view queries & reports created by users.
Select View Queries & Reports created by users; create and change queries and reports to create and change queries and reports.
Administrators can assign permissions for specific users from here. They can also select a group to view and edit the users that can access the systems in that group from System Tree using the System Tree Permissions option.
Note
Roles with System Tree Permissions options can be used to achieve an administrator role for a subset of System Tree.
Note
Other roles are also available based on the product you subscribed. For example, if you have subscribed for Trellix Mobile Security, then the default role is Trellix Mobile Security Administrator.
Click Save Changes.
The details show which permissions are assigned to the selected role.
Click Edit Assignments to view the User Assignments pane.
In the User Assignments pane, select the users for whom you want to assign the selected role.
Click Save Changes.