A role is a group of actions that a user is allowed to perform within a given administrative domain. Trellix IPS provides role-based authorization to the users.
Users authenticate themselves by logging into the Manager. For an admin domain, you can create users and assign roles to the users in the Manager. You can also create users in the child admin domains and assign roles to them.
The role privilege indicates the actions that are allowed for a user with assigned with the particular role. Each role has role privileges with Create, Edit, Run Only, or View Only permissions. For example, Configuration Reports - Create allows the user with that role to have Create permissions for the Reports in the Manager.
Trellix IPS includes default roles, and you can create new customizable roles. Users created for an admin domain are specific to that domain, but roles can be assigned to the users across domains. That is, you can assign a role to a user in one domain, and another role to the same user in the corresponding child domain.
The Roles option (Manager → <Admin Domain Name> → Users and Roles → Roles) lists the various default roles and allows you to create new customizable roles.
.png)
The following table lists the default role types and their corresponding role descriptions.
Note
Options to edit or delete are disabled for the default roles.
Role | Description | Role Privilege |
|---|---|---|
Policy Administrator | Administer the intrusion prevention environment | Configuration Reports - Create Dashboard and Analysis - Edit Deploy Pending Changes Event Reports - Create Policy - Edit Run Vulnerability Scan View Packet Captures |
NOC Operator | Monitor the security environment | Configuration Reports - Run Only Event Reports - Run Only View Packet Captures |
Report Generator | Run reports | Configuration Reports - Create Event Reports - Create |
Security Expert | Administer the IPS environment | Configuration Reports - Create Dashboard and Analysis - Edit Deploy Pending Changes Devices - View Only Event Reports - Create Manager - View Only Policy - Edit Run Vulnerability Scan View Packet Captures |
System Administrator | Administer the Manager and the Device List | Configuration Reports - Create Deploy Pending Changes Devices - Edit Event Reports - Run Only Manager - Edit Policy - View Only Synchronize Policy View Packet Captures |
ePO Dashboard Data Retriever | Rights to retrieve information from Trellix IPS to ePO, for displaying Trellix IPS information in the ePO. | ePO Dashboard Data Retrieval |
Super User | Full rights. Super Users must manage themselves within the domains they reside. | Configuration Reports - Create Configuration Reports - Run Only Dashboard and Analysis - Edit Dashboard and Analysis - View Only Deploy Pending Changes Devices - Add and Remove Devices - Edit Devices - View Only ePO Dashboard Data Retrieval Event Reports - Create Event Reports - Run Only Guest Portal User Account Manager Manager Central Manager - Edit Manager Central Manager - View Only Manage Managers - View Only Manager - Edit Manager - View Only Policy - Edit Policy - View Only User Auditing - Edit Users and Roles - Edit Users and Roles - View Only View Packet Captures |
No Role | The user cannot log on to Manager. This is the state when a user is first created but is yet to be assigned any role. |