System Roles
Focus
Focus
Prisma SD-WAN

System Roles

Table of Contents

System Roles

Learn about the pre-defined system roles in Prisma SD-WAN.
Where Can I Use This?What Do I Need?
  • Prisma SD-WAN
  • Prisma SD-WAN license
Prisma SD-WAN provides system roles with a pre-defined set of permissions. The table below describes Prisma SD-WAN system roles and responsibilities.
Prisma SD-WAN RolesPrisma SD-WAN Groups defined in a Customer IdP SystemResponsibilities
Multitenant Superusercloudgenix_tenant_root
Provides read and write access to manage all dashboards, reports, apps, Strata Logging Service logs, and services within the assigned level of nested hierarchy. Includes all permissions assigned to all roles, including Superuser, and the ability to activate product licenses through email activation link. Assign only to users or service accounts that require unrestricted access across multiple tenants.
Superuser (tenant_super_admin)cloudgenix_tenant_super
Provides read and write access to all available system-wide functions for the selected app. Includes all permissions assigned to all other roles, including MSP Superuser, granting unrestricted access across the system. Users with this role can activate product licenses through email activation links. Assign only to users or service accounts that require complete, unrestricted access to all system functions and configurations.
IAM Administrator (tenant_iam_admin)cloudgenix_tenant_iam_admin
Provides read and write access to identity and authentication functions for the selected app. Includes read-only access to logs. No access to dashboards and Strata Logging Service logs. Ideal for administrators who manage users and authentication processes.
Network Administrator (tenant_network_admin)cloudgenix_tenant_network_admin
Provides read and write access to logs, network policy configurations, and dashboards for the selected app. Includes read-only access to other functions including alerts, license quotas, devices, and tenant service group operations. Ideal for administrators who need to maintain authentication, certificates, and decryption rules. A network administrator performs the following configuration and monitoring functions:
  • Create, delete, edit sites.
  • Claim, declaim, assign device.
  • Configure the interface.
  • Create, delete, edit network policies.
  • Assign or un-assign network policies to sites.
  • Create, delete, edit network policy rules.
  • Create, delete, edit custom application definitions.
  • Create, delete, edit prefix filters.
  • Configure BGP and other routing objects like route maps, AS path lists, prefix filters.
  • Configure SNMP, Syslog, DNS service, IPFIX, and IP community lists on data center and branch device,
  • Monitor security flows.
  • Monitor traffic utilization through network and application performance activity charts.
Security Administrator (tenant_security_admin)cloudgenix_tenant_security_admin
Provides read and write access security policy configuration and dashboard functionality. This role also provides read-only access to other functions, including but not limited to alerts, license quotas, devices, and tenant service group operations. Ideal for users responsible for managing and maintaining security policies across the system. A security administrator performs the following configuration and monitoring functions:
  • Create, delete, edit security zones.
  • Bind or unbind zones to sites.
  • Create, delete, edit security rules.
  • Bind or unbind security policies to sites.
  • Monitor security flows.
  • Monitor traffic utilization through network and application performance activity charts.
View-only User (tenant_viewonly)cloudgenix_tenant_viewonly
Provides read-only access to all available system-wide functions for the selected app and logs. Allows users to view dashboards, download, share, and schedule reports, providing comprehensive visibility without the ability to make changes. Ideal for users who need to monitor and analyze system-wide information but should not have permissions to modify configurations or settings. A view-only user may view the following:
  • View device/interface configuration.
  • View network policies.
  • View security policies.
  • View system and custom applications.
  • View prefix filters.
  • Monitor security flows.
  • Monitor traffic utilization through network and application performance activity chart.

Related CLIs