| Where Can I Use This? | What Do I Need? |
|
|
One of the following subscriptions:
Device Security subscription
Precision AI bundle subscription
Device Security X subscription
|
Define custom
role-based access
control roles for
Device Security in Identity & Access
Management (IAM) in
Strata Cloud Manager, not within
Device Security
itself. A role is a named collection of per-entity permissions -
Read Write,
Read Only, or
No Access - that you assign to
users. Changes to a role definition propagate to every user assigned that role.
The Superuser and View Only
Administrator roles are predefined and cannot be edited,
cloned, or deleted. Use custom roles for any permission combination that
the predefined roles do not provide.
Before you define a Device Security role, verify the following:
You manage your Device Security solution in Strata Cloud Manager.
You have the Superuser role in Strata Cloud Manager. Only superuser
administrators can create, modify, or delete custom
Device Security roles.
You're familiar with the
Device Security entities that RBAC can
gate. For the full list of entities and the three-tier permission
model, see
Role-Based
Access Control.