Enable Role Based Access to Advanced IP Defense
Focus
Focus
Advanced IP Defense

Enable Role Based Access to Advanced IP Defense

Table of Contents

Enable Role Based Access to Advanced IP Defense

Configure role-based access to Advanced IP Defense by assigning predefined or custom roles to your security administrators.
Where Can I Use This?What Do I Need?
  • NGFW (Managed by Strata Cloud Manager)
  • NGFW (Managed by PAN-OS or Panorama)
  • VM-Series
  • Advanced IP Defense license
  • PAN-OS 12.2.3 and later
Configure role-based access to Advanced IP Defense to control which administrators can view and modify Advanced IP Defense profiles, zones, and logs.
On NGFW and Panorama® management server, role-based access uses a custom admin role profile. If an administrator already has an admin role associated with their account, you can update it to include Advanced IP Defense access privileges.
On Strata Cloud Manager, role-based access uses predefined roles assigned through Identity & Access. The role you assign determines which parts of Advanced IP Defense each administrator can access. For details about all predefined roles and their access privileges, review Roles and Permissions.
Predefined Role
Privileges
Superuser
Full read and write privileges for the tenant, including Advanced IP Defense profile configuration, zone attachment, and log access.
Security Administrator
Read and write access for Advanced IP Defense profile configuration and zone attachment.
Multitenant Superuser
Full read and write privileges for all available system-wide functions, including Advanced IP Defense, for all tenants in the multitenant hierarchy where the role is assigned.
View Only Administrator
Read-only privileges for Advanced IP Defense profiles, zone configurations, and logs.

Enable Role Based Access for Advanced IP Defense on Strata Cloud Manager

Assign predefined or custom roles through Strata Cloud Manager to control access to Advanced IP Defense features.
  1. Log in to Strata Cloud Manager.
  2. (New administrators only) Add Access to your tenant where you have an Advanced IP Defense.
    This step is required only if the administrator you are granting Advanced IP Defense access to is not already registered with the Palo Alto Networks Customer Support Portal (CSP).
  3. Select System SettingsIdentity & Access Management and select one or more administrators.
    1. Select User and for Identity Address, enter the email address for the administrator you added in the previous step.
    2. For Apps & Services, select Advanced IP Defense.
    3. Select one of the supported predefined Role.
  4. Click Assign Roles.
  5. For the Apps & Services, select one of the following:
    • All Apps & Services—Applies the access privileges for the predefined role to all apps and services available on your tenant.
    • Prisma Access & NGFW Configuration—Applies the access privileges for the predefined roll only for the configuration objects available in ConfigurationPrisma Access & NGFW Configuration.
  6. (Optional) Add Another to configure additional role-based access to other apps and services.
  7. Submit.

Enable Role Based Access for Advanced IP Defense on NGFW

Configure an admin role on a standalone NGFW to control access to Advanced IP Defense features.
  1. Log in to the NGFW web interface.
  2. Configure the NGFW admin role.
    This controls the access privileges to the Advanced IP Defense profile configuration an administrator has directly on the NGFW web interface.
    1. Select DeviceAdmin Roles.
    2. Add a new admin role or select an existing role to modify.
    3. In the Web UIObjectsSecurity Profiles admin role privileges, configure the Advanced IP Defense access privileges.
      The Advanced IP Defense permissions control access to profile configuration, zone attachment, and threat log visibility. Set each permission to Enable, Read Only, or Disable based on the level of access required for the administrator.
    4. Click OK to save the admin role.
  3. Select DeviceAdministrators and assign the admin role to the appropriate administrator accounts.
  4. Commit your changes.

Enable Role Based Access for Advanced IP Defense on Panorama

Configure an admin role on Panorama® management server to control access to Advanced IP Defense features pushed to managed devices.
Role-based access on Panorama® management server operates at two levels: the Panorama admin role controls access to Advanced IP Defense configuration pushed to managed devices, and the NGFW admin role controls access directly on each managed NGFW web interface.
  1. Log in to the Panorama web interface.
  2. Configure the Panorama admin role.
    This controls the Panorama administrator access privileges to the Advanced IP Defense profile configuration pushed to managed devices.
    1. Select PanoramaAdmin Roles.
    2. Add a new admin role or select an existing role to modify.
    3. In the Web UIObjectsSecurity Profiles admin role privileges, configure the Advanced IP Defense access privileges.
      The Advanced IP Defense permissions control access to profile configuration, zone attachment, and threat log visibility. Set each permission to Enable, Read Only, or Disable based on the level of access required for the administrator.
    4. Click OK to save the admin role.
  3. Select PanoramaAdministrators and assign the admin role to the appropriate administrator accounts.
  4. Configure the NGFW admin role.
    This controls the access privileges to the Advanced IP Defense profile configuration an administrator has directly on the NGFW web interface.
    1. Select DeviceAdmin Roles and select the Template that your managed devices using Advanced IP Defense belong to.
    2. Add a new admin role or select an existing role to modify.
    3. In the Web UIObjectsSecurity Profiles admin role privileges, configure the Advanced IP Defense access privileges.
      The Advanced IP Defense permissions control access to profile configuration, zone attachment, and threat log visibility. Set each permission to Enable, Read Only, or Disable based on the level of access required for the administrator.
    4. Click OK to save the admin role.
  5. Select DeviceAdministrators and select the Template that your managed devices using Advanced IP Defense belong to, then assign the admin role to the appropriate administrator accounts.
  6. Select CommitCommit and Push to commit changes to Panorama and push them to managed devices.