Prisma SD-WAN
System Roles
Table of Contents
Expand All
|
Collapse All
Prisma SD-WAN Docs
-
-
-
- CloudBlade Integrations
- CloudBlades Integration with Prisma Access
-
-
-
-
- 6.5
- 6.4
- 6.3
- 6.2
- 6.1
- 5.6
- New Features Guide
- On-Premises Controller
- Prisma SD-WAN CloudBlades
- Prisma Access CloudBlade Cloud Managed
- Prisma Access CloudBlade Panorama Managed
System Roles
Learn about the pre-defined system roles in Prisma SD-WAN.
Where Can I Use This? | What Do I Need? |
---|---|
|
|
Prisma SD-WAN provides system roles with
a pre-defined set of permissions. The table below describes Prisma
SD-WAN system roles and responsibilities.
Prisma SD-WAN Roles | Prisma SD-WAN Groups defined in a Customer IdP System | Responsibilities |
---|---|---|
Multitenant Superuser | cloudgenix_tenant_root | Provides read and write access to manage all dashboards, reports, apps, Strata Logging Service
logs, and services within the assigned level of nested hierarchy.
Includes all permissions assigned to all roles, including Superuser,
and the ability to activate product licenses through email
activation link. Assign only to users or service accounts that
require unrestricted access across multiple tenants. |
Superuser (tenant_super_admin) | cloudgenix_tenant_super | Provides read and write access to all available system-wide functions for the selected app.
Includes all permissions assigned to all other roles, including MSP
Superuser, granting unrestricted access across the system. Users
with this role can activate product licenses through email
activation links. Assign only to users or service accounts that
require complete, unrestricted access to all system functions and
configurations. |
IAM Administrator (tenant_iam_admin) | cloudgenix_tenant_iam_admin | Provides read and write access to identity and authentication functions for the selected app.
Includes read-only access to logs. No access to dashboards and
Strata Logging Service logs. Ideal for administrators who manage
users and authentication processes. |
Network Administrator (tenant_network_admin) | cloudgenix_tenant_network_admin | Provides read and write access to logs, network policy configurations, and dashboards for the
selected app. Includes read-only access to other functions including
alerts, license quotas, devices, and tenant service group
operations. Ideal for administrators who need to maintain
authentication, certificates, and decryption rules. A network
administrator performs the following configuration and monitoring
functions:
|
Security Administrator (tenant_security_admin) | cloudgenix_tenant_security_admin | Provides read and write access security policy configuration and dashboard functionality. This
role also provides read-only access to other functions, including
but not limited to alerts, license quotas, devices, and tenant
service group operations. Ideal for users responsible for managing
and maintaining security policies across the system. A security
administrator performs the following configuration and monitoring
functions:
|
View-only User (tenant_viewonly) | cloudgenix_tenant_viewonly | Provides read-only access to all available system-wide functions for the selected app and logs.
Allows users to view dashboards, download, share, and schedule
reports, providing comprehensive visibility without the ability to
make changes. Ideal for users who need to monitor and analyze
system-wide information but should not have permissions to modify
configurations or settings. A view-only user may view the following:
|
Related CLIs
- config banner
- debug log agent eal file log
- debug logging facility
- debug logs dump
- debug logs follow
- debug logs tail
- debug process
- debug reboot
- debug service link logging
- debug time sync
- file export
- file remove
- file space available
- file tailf log
- file view log
- inspect certificate
- inspect cgnx infra role
- inspect connection
- inspect process status
- inspect switch mac address table
- dump auth config
- dump auth status
- dump banner config
- dump device accessconfig
- dump device conntrack count
- dump device date
- dump device info
- dump device status
- dump radius config
- dump radius statistics
- dump radius status
- dump sensor type
- dump sensor type summary
- dump time config
- dump time log
- dump time status
- dump troubleshoot message
- clear switch mac address entries
- clear device account login