Define Device Security Roles
Focus
Focus
Device Security

Define Device Security Roles

Table of Contents

Define Device Security Roles

Create, modify, and delete custom Device Security roles in Strata Cloud Manager to control which actions users can perform on each entity.
Where Can I Use This?What Do I Need?
  • Device Security (Managed by Strata Cloud Manager)
One of the following subscriptions:
  • Device Security subscription
  • Precision AI bundle subscription
  • Device Security X subscription
Define custom role-based access control roles for Device Security in Identity & Access Management (IAM) in Strata Cloud Manager, not within Device Security itself. A role is a named collection of per-entity permissions - Read Write, Read Only, or No Access - that you assign to users. Changes to a role definition propagate to every user assigned that role.
The Superuser and View Only Administrator roles are predefined and cannot be edited, cloned, or deleted. Use custom roles for any permission combination that the predefined roles do not provide.
Before you define a Device Security role, verify the following:
  • You manage your Device Security solution in Strata Cloud Manager.
  • You have the Superuser role in Strata Cloud Manager. Only superuser administrators can create, modify, or delete custom Device Security roles.
  • You're familiar with the Device Security entities that RBAC can gate. For the full list of entities and the three-tier permission model, see Role-Based Access Control.
  1. In Strata Cloud Manager, select System SettingsIdentity & Access ManagementRoles.
    The Roles panel shows the tenants available to you.
  2. Optional Select the tenant that you want to create or edit roles for.
    The panel displays two tabs: Predefined Roles and Custom Roles. The Predefined Roles tab lists the Superuser and View Only Administrator roles that Strata Cloud Manager provides for every tenant. You cannot edit, clone, or delete predefined roles.
  3. Select the Custom Roles tab and click Add Custom Role.
    The Custom Roles tab lists every custom role already defined for the selected tenant. To edit or delete an existing custom role, click the Actions (gear icon) in the row for that role.
  4. Enter the required Name and Description for the role. Optionally, enter a Display Name.
    Role names must be unique within the tenant. We recommend using a name that identifies the team or function the role is intended for, such as SOC Analyst or Network Manager. If you enter a Display Name, Strata Cloud Manager shows it in place of the internal role name wherever the role is referenced.
  5. Optional Click Clone a Role to start from an existing role definition, and then adjust the permissions that differ.
  6. Under Permissions, expand Device Security and set the permission level for each entity by clicking the permission icon.
    Device Security gates access to the following entities: Administration, Alerts, Dashboard & Reports, Devices, Integration, Medical, Networks, Policies, Queries & Filters, Risk Factors, and Vulnerabilities.
    The three permission levels behave as follows:
    • Read Write (green check icon) - The user can view and modify the entity, including create, edit, resolve, or delete actions where applicable.
    • Read Only (blue eye icon) - The user can view the entity and its associated pages, widgets, and API responses, but cannot make changes.
    • No Access (red slashed-eye icon) - The entity is hidden from the user's navigation, and related widgets, pages, and API calls return no data or return a 403 response.
  7. Confirm that Devices is set to Read Only or Read Write.
  8. Click Save.
  9. Optional Edit a custom role by returning to System SettingsIdentity & Access ManagementRoles, selecting the tenant, opening the Custom Roles tab, and clicking the name of the role you want to edit.
    You can edit custom roles that are currently assigned to users. Changes to the role propagate to every user assigned that role. Users must log out of Strata Cloud Manager and log back in for the updated permissions to take effect.
  10. Optional Delete a custom role by returning to the Custom Roles tab for the tenant, clicking the Actions (gear icon) in the row for the role, and then selecting the delete option.
    You cannot delete a custom role that is currently assigned to one or more users. To delete a role, first remove it from every user it is assigned to.