Creating child domains enables you to delegate, monitor, and/or configure Trellix IPS Sensors in that sub-domain to entities more familiar with the sub-domain's environment. You are not required to subdivide your admin domains into child domains; however, if you want to delegate responsibilities for managing Trellix IPS resources among multiple individuals within your organization, you do so by creating child domains. To delegate responsibilities, you create child admin domains and user accounts, giving each user a role that defines how the user can interact with the resources in the child admin domain.
For example, suppose you manage three Trellix IPS Sensors. You can create a child domain and allocate a single port (G0/1) from one of your Sensors to that domain. You can create a user and assign that person a Super User role in only that domain; that user has no role in the root domain, and therefore cannot see or configure root domain resources. The child domain's Super User has been delegated full management responsibilities for the allocated interface.
A user's role determines his/her view of the Resource Tree; only resources the user is permitted to view are displayed in the tree.
Any domain with child domains is a parent; thus, a child domain can be a parent to other child domains. When you create a child domain you can enable or disable it to be a parent for other domains (enabled by default). The root can always have child domains.
It is important to understand the relationship between parent and child admin domains because child admin domains inherit policies from parent admin domains, and users inherit the same privileges in the child domains as enabled by their roles in the parent domain.
Note
Throughout this guide, named admin domain instances are represented as <Admin Domain Name>. The default root admin domain is My Company.