Next-Generation Firewall
Configure an Admin Role Profile (Strata Cloud Manager)
Table of Contents
Expand All
|
Collapse All
Next-Generation Firewall Docs
-
-
-
-
-
-
-
- PAN-OS 12.1
- PAN-OS 11.2
- PAN-OS 11.1
- PAN-OS 11.0 (EoL)
- PAN-OS 10.2
- PAN-OS 10.1
- PAN-OS 10.0 (EoL)
- PAN-OS 9.1 (EoL)
- PAN-OS 9.0 (EoL)
- PAN-OS 8.1 (EoL)
-
- PAN-OS 12.1
- PAN-OS 11.2
- PAN-OS 11.1
- PAN-OS 10.2
- PAN-OS 10.1
Configure an Admin Role Profile (Strata Cloud Manager)
In Strata Cloud Manager, you can create and customize admin role profiles to define
granular access permissions. You can control which parts of the firewall
configuration an administrator can manage across the web UI, REST API, XML API, and
command line interfaces.
- Select Device SettingsAdmin Roles and click Add Admin Role.Enter a Name to identify the role.In the Web UI and REST API tabs, select the required feature to toggle it to the desired setting: Enable, Read Only or Disable. For the XML API tab select, Enable or Disable. For details on the Web UI options, see Web Interface Access Privileges.Select the Command Line tab and select a CLI access option.
- None—CLI access is not permitted (default).
- superuser—Full access. Can define new administrator accounts and virtual systems. Only a superuser can create administrator users with superuser privileges.
- superreader—Full read-only access.
- deviceadmin—Full access to all settings except defining new accounts or virtual systems.
- devicereader—Read-only access to all settings except password profiles (no access) and administrator accounts (only the logged in account is visible).
Click OK to save the profile.Assign the role to an administrator. See Configure a Firewall Administrator Account.