The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Create an IAM role

Prev Next

An IAM role is created in the Azure console which is required for the Controller and Manager communication. With the help of the IAM role, the Controller retrieves information about users from the Manager.

Note

You must assign the IAM role to the Local Controller or External Controller instance for the Controller and Manager communication. In case of Local Controller, you must assign the IAM role to the Manager instance itself.

To create a IAM role in Azure, perform the following steps:

Task

  1. Click All services. Under Identity category, click Managed Identity.
  2. Click + Add.
    The Create User Assigned Managed Identity window along with the Basics tab opens.
  3. On the Basics tab, enter the following details:
    Option Definition
    PROJECT DETAILS

    Subscription - The subscription linked with your Azure account is selected by default. If you have multiple subscription accounts, select the subscription account in which you would like to launch the Manager virtual machine.

    Resource group

    • Create new - You can create a new resource group to be protected.
    • Use existing - Select a resource group from the existing resource groups to be protected.
    INSTANCE DETAILS

    Region - Select the region where the managed identity must be created.

    Name - Type a name for the User Assigned Managed Identity.

    Note

    The User Assigned Managed Identity name should not exceed 25 characters.

    Note

    Azure validates the information you enter and a green tick appears against the fields where you enter details.

  4. Click Next: Tags >.

    The Tags tab opens. On this tab, you can categorize resources by applying a tag name and value to multiple resources and resource groups.

  5. Click Next: Review + create >.
    The Review + create tab opens. Validate the summary details which contains all the parameters selected. Make sure the validation is successful.
  6. Click Create.
    The user assigned managed identity is created.
  7. Go to All Services → Identity → Managed Identity and select the newly created User assigned managed identity.
    A page with details of the selected user assigned managed identity opens.
  8. Click Access control (IAM).
    The Access control (IAM) window opens.

    Note

    You require Owner access to add permissions to the registered application.

  9. Click Add role assignments.
  10. In the Add role assignments window, enter the following details:
    Option Definition
    Role Select a pre-defined role from the drop-down. The minimum required role is Reader. You can select Contributor or Owner as well.
    Assign access to Select User, group or service principal.
    Select Search and select the user based managed identity for which the role needs to be assigned.
  11. Click Save.