Device Security
Strata Cloud Manager
Table of Contents
Expand All
|
Collapse All
Device Security Docs
Strata Cloud Manager
Create Device Security users, assign user roles, and view users in
Device Security in Strata Cloud Manager.
For Device Security in Strata Cloud Manager, use the Identity & Access
Management services to manage all user roles and scopes. You can allow users to
authenticate using the Palo Alto Networks SSO, or using a third-party identity
provider (IdP).
- Set up authentication for your Device Security users.
- Palo Alto Networks SSO Add User Access Through Common Services
- Third-party IdP SSO Manage Third-Party Identity Provider Integrations Through Common ServicesIf you activated Device Security before June 2025 and use a third-party IdP SSO, you need to reconfigure your third-party IdP through Common Services to access Device Security in Strata Cloud Manager.
Create Device Security scopes through the Strata Cloud Manager Identity & Access Management.Navigate to System SettingsIdentity & Access ManagementScopes to view all scope objects within your TSG.Device Security scopes are defined using sites:- All
- None
- Custom Selection
Administrators can use the Custom Selection option to grant users access to a subset of sites defined within Device Security. Selecting a site group or the organization will select all sites within that group. Users who have been granted access to a group will automatically be granted access to new sites within the group.Assign a predefined role and scopes to a tenant user or service account through Strata Cloud Manager Identity & Access Management.Strata Cloud Manager uses Identity & Access Management to manage user roles and scopes. From the enterprise roles available in Identity & Access Management, Device Security supports the Superuser role and the View Only Administrator role.For customers transitioning from the Device Security portal to Device Security in Strata Cloud Manager, the Device Security user roles map to the following Strata Cloud Manager roles:- Owner -> Superuser
- Administrator -> Superuser
- Read-only -> View-only Administrator
Periodically review all users and roles with access to Device Security and remove user access through Common Services as needed.