Authenticate Users with Any SSO and Manage User Roles in the Device Security Portal
User roles are set for user accounts in external SSO authentication systems — the
Palo Alto Networks SSO and customer-managed SSOs—but you can also log in to the
Device Security portal with owner privileges and set other roles for administrators
and read-only users. If the externally and internally managed roles are
different, Device Security assigns the higher of the two. Therefore, only set user
roles internally on Device Security that are higher than those set externally;
otherwise, an internal role will never be assigned. The ranking of roles from
highest to lowest is owner, administrator, read-only user.
If user accounts in an external SSO don't have any externally managed roles
defined, these users won't be able to log in to Device Security until a local user
with owner privileges sets internally managed roles for them and invites them to
log in to Device Security.