The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Granular access control for CLI commands

Prev Next

Trellix Intrusion Prevention System supports creation of multiple user accounts for the Sensor. Each of these user accounts is created for various functions, that is, different roles are associated with these user accounts. The role of a user determines the CLI commands he or she is able to access.

The following Sensor user roles are supported:

  • Admin – Access to all commands

  • Read and Write – Access to all commands, except the ones available only to the administrator

  • Read Only – Access to all show commands

  • Updater – Access to update Sensor images and signature files

  • Maintainer – Access to update Sensor images, signature files, and also adding a Sensor to a specific Manager

Note

The debug commands can be accessed by admins or users with read and write access.

You can authenticate users by using either TACACS+ or RADIUS servers. For a TACACS+ user to obtain granular access control, authorization should be enabled at the Sensor. If not, Admin access is given to the user. The role should be assigned in the TACACS+ server configuration. If no role is configured in the TACACS+ server, Admin access is given. If a role other than the allowed roles is assigned, Read-Only access is given. Users authenticated by RADIUS server are assigned the Admin role by default. Role based user logins cannot be created through the RADIUS server.

The following is an example of the TACACS+ server configuration file:

user=user1 {

................

................

service = intrushell {

role= “RO-Access”

}

}

Note

In case of RADIUS configuration, the role is assigned as Admin by default.

The allowed strings to be given in the TACACS+ configuration file are the following:

  • “Updater”

  • “Maintainer”

  • “RO-Access”

  • “RW-Access”

  • “Admin-Access”

Note

Trellix recommends either TACACS+/RADIUS users or local users on the Sensor are configured. If both are required, ensure that users with the same name are not present in the Sensor and the TACACS+/RADIUS servers.