The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Define Roles

Prev Next

A role is a group of actions that a user is allowed to perform within a given administrative domain. Trellix IPS provides role-based authorization to the users.

Users authenticate themselves by logging into the Manager. For an admin domain, you can create users and assign roles to the users in the Manager. You can also create users in the child admin domains and assign roles to them.

The role privilege indicates the actions that are allowed for a user with assigned with the particular role. Each role has role privileges with Create, Edit, Run Only, or View Only permissions. For example, Configuration Reports - Create allows the user with that role to have Create permissions for the Reports in the Manager.

Trellix IPS includes default roles, and you can create new customizable roles. Users created for an admin domain are specific to that domain, but roles can be assigned to the users across domains. That is, you can assign a role to a user in one domain, and another role to the same user in the corresponding child domain.

The Roles option (Manager → <Admin Domain Name> → Users and Roles → Roles) lists the various default roles and allows you to create new customizable roles.

Roles page
Roles page


The following table lists the default role types and their corresponding role descriptions.

Note

Options to edit or delete are disabled for the default roles.

Role

Description

Role Privilege

Policy Administrator

Administer the intrusion prevention environment

Configuration Reports - Create

Dashboard and Analysis - Edit

Deploy Pending Changes

Event Reports - Create

Policy - Edit

Run Vulnerability Scan

View Packet Captures

NOC Operator

Monitor the security environment

Configuration Reports - Run Only

Event Reports - Run Only

View Packet Captures

Report Generator

Run reports

Configuration Reports - Create

Event Reports - Create

Security Expert

Administer the IPS environment

Configuration Reports - Create

Dashboard and Analysis - Edit

Deploy Pending Changes

Devices - View Only

Event Reports - Create

Manager - View Only

Policy - Edit

Run Vulnerability Scan

View Packet Captures

System Administrator

Administer the Manager and the Device List

Configuration Reports - Create

Deploy Pending Changes

Devices - Edit

Event Reports - Run Only

Manager - Edit

Policy - View Only

Synchronize Policy

View Packet Captures

ePO Dashboard Data Retriever

Rights to retrieve information from Trellix IPS to ePO, for displaying Trellix IPS information in the ePO.

ePO Dashboard Data Retrieval

Super User

Full rights. Super Users must manage themselves within the domains they reside.

Configuration Reports - Create

Configuration Reports - Run Only

Dashboard and Analysis - Edit

Dashboard and Analysis - View Only

Deploy Pending Changes

Devices - Add and Remove

Devices - Edit

Devices - View Only

ePO Dashboard Data Retrieval

Event Reports - Create

Event Reports - Run Only

Guest Portal User Account Manager

Manager Central Manager - Edit

Manager Central Manager - View Only

Manage Managers - View Only

Manager - Edit

Manager - View Only

Policy - Edit

Policy - View Only

User Auditing - Edit

Users and Roles - Edit

Users and Roles - View Only

View Packet Captures

No Role

The user cannot log on to Manager. This is the state when a user is first created but is yet to be assigned any role.